Impact
The vulnerability arises from a NULL pointer dereference that can cause a stable crash in the operating system. When triggered, the affected IBM AIX 7.2, 7.3 or PowerVM VIOS 4.1 services become unavailable, leading to a loss of availability for the host or virtual environment. The weakness is identified as CWE‑476, a null dereference leading to memory violation. The CVSS score of 4.7 indicates moderate severity and the impact is confined to system availability rather than confidentiality or integrity.
Affected Systems
IBM AIX versions 7.2 and 7.3, including all service pack levels prior to the listed SPs, and IBM PowerVM VIOS 4.1 series before the published fix packs. Specific remediation levels are AIX Service Pack 2 for TL04, 3 for TL03, 5 for TL02, and 13 for TL05; for VIOS the applicable Fix Pack levels are 4.1.2.20 for 4.1.2, 4.1.1.30 for 4.1.1, and 4.1.0.50 for 4.1.0.
Risk and Exploitability
The CVSS score of 4.7 places this issue in a moderate category, and no exploit probability score from EPSS is available, suggesting uncertainty about imminent exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation campaigns. Based on the description, the attack vector is inferred to be local, meaning an attacker with local access can trigger the crash. Mitigation requires applying the provider‑issued patches or service packs.
OpenCVE Enrichment