Impact
IBM AIX 7.2, AIX 7.3, and PowerVM VIOS 4.1 contain a flaw that permits a remote attacker to trigger a denial of service by sending requests that bypass allocation size validation, leading to resource exhaustion or a system crash. The weakness is classified as improper resource handling (CWE-770).
Affected Systems
Affected versions include IBM AIX 7.2 and 7.3 with service packs AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, and AIX 7.2 TL05 SP13, as well as PowerVM VIOS 4.1.0, 4.1.1, and 4.1.2 with the corresponding fix pack levels 4.1.0.50, 4.1.1.30, and 4.1.2.20.
Risk and Exploitability
The CVSS score of 7.5 classifies this vulnerability as high severity, and the EPSS score is not available, so no indication of current exploitation patterns is provided. The vulnerability is exploitable remotely through interfaces that allow allocation requests; an attacker can cause a restart or complete denial of service for all users sharing the affected system. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment