Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain a kernel heap over-read vulnerability that can be exploited by a remote attacker to read sensitive data and trigger a system crash. The flaw provides both confidential data leakage and availability disruption, with no authentication or privilege escalation required by the description.
Affected Systems
Affected systems include IBM AIX versions 7.2 and 7.3, as well as PowerVM VIOS 4.1. IBM recommends applying the Service Packs listed as the remediation levels for AIX (SP2, SP3, SP5, SP13 across various TLs) and the Fix Packs for VIOS (4.1.0.50, 4.1.1.30, 4.1.2.20). These packs are cumulative and cover all earlier vulnerabilities. A LPAR reboot is required for the update to take effect, though Live Update can be used on AIX to avoid a reboot. VIOS 4.1.0 and 4.1.1 also require migration to PostgreSQL 15 after the patch, with IBM providing specific post-update instructions.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the EPSS score is unavailable, implying the exploitation probability is unknown but potentially significant. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is a remote connection that can manipulate the kernel heap, leading to memory over-read, information disclosure, and service interruption.
OpenCVE Enrichment