Impact
A remote attacker can trigger a buffer overflow in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1, causing the affected system to become unresponsive. The flaw matches CWE‑787. The impact is a loss of availability for processes or the entire operating system, depending on the severity of the overflow and how the target system responds.
Affected Systems
IBM AIX version 7.2 and 7.3 on any installation level prior to the published Service Packs, and IBM PowerVM VIOS 4.1 on any level prior to the published Fix Packs are affected. The specific remediation levels are AIX 7.2 TL05 SP13, AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, and AIX 7.3 TL02 SP5; for VIOS, the Fix Packs are 4.1.0.50 for 4.1.0, 4.1.1.30 for 4.1.1, and 4.1.2.20 for 4.1.2. These patches are cumulative and can be applied over earlier levels.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is provided, and the vulnerability is not listed in CISA’s KEV catalogue, suggesting limited exploitation activity so far. The likely attack vector is remote: an attacker must send specially crafted input to a vulnerable component to overflow the buffer and destabilize the system.
OpenCVE Enrichment