Impact
The vulnerability is an out-of-bounds read that allows a local attacker to read memory locations outside the intended bounds. This can lead to disclosure of sensitive information or possibly trigger a denial of service by causing the affected process to crash. The weakness is classified as CWE-125.
Affected Systems
Affected platforms are IBM AIX versions 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1. For AIX, Service Packs covering the issue are AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, and AIX 7.2 TL05 SP13. For PowerVM VIOS, the relevant Fix Packs are VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.0 4.1.0.50. These levels are cumulative and include fixes for all previously published vulnerabilities.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium risk level. Because the vulnerability requires local execution, the attack surface is limited to users with physical access or impact from malicious users who can run code on the system. The EPSS score is not available, so the likely exploitation probability is unknown but the vulnerability is not listed in the CISA KEV catalog. There is no external remote exploit path documented; if the attacker can trigger the read locally, sensitive data may be exposed, compromising confidentiality.
OpenCVE Enrichment