Impact
The vulnerability is caused by improper validation of symbolic links within IBM AIX 7.2/7.3 and IBM PowerVM VIOS 4.1, allowing a local attacker to trigger a denial of service. An attacker who can read or write files within the affected file system can create or manipulate symbolic links that cause the operating system or virtual infrastructure to become unresponsive. This weakness is classified as CWE‑59.
Affected Systems
The flaw affects IBM AIX versions 7.2 and 7.3, including all sub‑release levels covered by Service Packs 7.2 TL05 SP13, 7.3 TL04 SP2, 7.3 TL03 SP3, and 7.3 TL02 SP5. It also applies to IBM PowerVM VIOS 4.1.0, 4.1.1, and 4.1.2, as addressed by Fix Packs 4.1.0.50, 4.1.1.30, and 4.1.2.20. All affected environments are listed on IBM Fix Central under the specified APAR numbers.
Risk and Exploitability
IBM assigns a CVSS score of 6.3 to this issue, indicating a moderate impact when succeeded. No EPSS score is available, and the vulnerability is not catalogued in CISA KEV. The attack vector is local, meaning that the threat is limited to users who already have access to the affected system. The advisory recommends patching as a priority, because the vulnerability can disrupt service for an entire system or virtual OS without involving remote code execution. The recommended remediation levels are the cumulative Service Packs and Fix Packs, which can be applied from Fix Central; a reboot of the logical partition is required unless the AIX Live Update mechanism is used.
OpenCVE Enrichment