Impact
A local attacker can read beyond allocated memory bounds when interacting with certain components of IBM AIX 7.2, 7.3, or PowerVM VIOS 4.1, which may lead to arbitrary code execution. The weakness corresponds to CWE‑125 – Out‑of‑Bounds Read. No data is provided about information disclosure or privilege escalation beyond what is necessary to run malicious code on the host.
Affected Systems
IBM AIX versions 7.2.0 to 7.2.5 and all 7.3.x releases such as 7.3 TL04, TL03, TL02, TL05, and Service Pack 13 are affected. For IBM PowerVM VIOS the vulnerability spans version 4.1.0 (up to 4.1.0.50) and 4.1.1 (up to 4.1.1.30), as well as 4.1.2. The fixes include cumulative Service Packs for AIX and cumulative Fix Packs for VIOS.
Risk and Exploitability
The CVSS score of 7.8 classifies this as High severity, and the absence of an EPSS score means the exploitation probability is uncertain but potentially non‑negligible. The vulnerability is accessed through local privileges – a user with local access to the affected system can trigger the out‑of‑bounds read. The CVE is not currently listed in the CISA KEV catalog, so it has not been observed in widespread exploitation, but the high severity warrants immediate mitigations. Rebooting the LPAR after applying the Service Pack or Fix Pack is required, except for AIX where Live Update can be used to avoid a reboot.
OpenCVE Enrichment