Impact
An integer overflow during size computation in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 allows a remote attacker to execute arbitrary code. The flaw can corrupt memory or hijack control flow, giving the attacker full compromise of the affected host. The weakness corresponds to CWE‑190 Integer Overflow or Underflow.
Affected Systems
The vulnerability affects IBM AIX 7.2 and 7.3 series and IBM PowerVM VIOS 4.1. The specific affected releases include AIX 7.2.0 through 7.2 TL05 SP13, AIX 7.3 0 through 7.3 TL04 SP2, and VIOS 4.1.0, 4.1.1 and 4.1.2 with their respective fix‑pack levels up to 4.1.2.20. These systems run on IBM Power servers.
Risk and Exploitability
The CVSS score of 9.8 indicates that exploitation is highly damaging and can be achieved remotely. EPSS is not available, and the flaw is not listed in CISA KEV, but the high severity and lack of prerequisite privileges mean that anyone with network access could trigger the overflow. An LPAR reboot is required to complete the SP/FP update unless Live Update is used on AIX. Immediate patching is essential to prevent remote code execution.
OpenCVE Enrichment