Impact
The vulnerability is an out-of-bounds read in the kernel that enables a local attacker to read sensitive kernel memory. This can expose confidential data such as credentials, cryptographic keys, or other sensitive information, thereby compromising confidentiality. The weakness is classified as information disclosure and does not provide direct remote code execution or privilege escalation capability.
Affected Systems
IBM AIX releases 7.2 and 7.3 are affected, with mitigations available in Service Pack levels SP13 for 7.2 and SP2, SP3, SP5 for various 7.3 maintenance levels. IBM PowerVM VIOS 4.1 series, including 4.1.0, 4.1.1, and 4.1.2, are also impacted and require Fix Pack levels 4.1.0.50, 4.1.1.30, and 4.1.2.20. The defined APARs provide the official patching paths for each affected version.
Risk and Exploitability
With a CVSS score of 5.5, the risk is moderate. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no current evidence of widespread exploitation. The likely attack vector is local; a user with local or privileged access would need to induce the out-of-bounds read to read kernel memory. Although the vulnerability lacks remote exploitation potential, the impact on data confidentiality makes timely patching important.
OpenCVE Enrichment