Impact
IBM AIX 7.2, AIX 7.3, and IBM PowerVM VIOS 4.1 contain an out‑of‑bounds write vulnerability that can be triggered by a local attacker. This flaw allows the attacker to corrupt memory and cause a service interruption, resulting in a denial of service.
Affected Systems
The vulnerability affects AIX 7.2 and 7.3 as well as PowerVM VIOS 4.1 on any release lower than the Service Packs and Fix Packs described in the CVE. IBM has assigned specific remediation levels, including AIX Service Pack 2 for TL 04, Service Pack 3 for TL 03, Service Pack 5 for TL 02, and Service Pack 13 for 7.2; for PowerVM VIOS the relevant versions are Fix Pack 4.1.0.50, 4.1.1.30, and 4.1.2.20. Patches are cumulative and include fixes for all previously published AIX/VIOS vulnerabilities.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate impact and the vulnerability is local in scope. EPSS is not available, and the flaw is not listed in the CISA KEV catalog, implying that no publicly known exploits have yet been observed. The most likely attack vector is an authenticated local user who can trigger the out‑of‑bounds write, potentially leading to an immediate denial of service. Because only a local attacker can exploit this, the risk remains contained but should still be addressed promptly to prevent service outages.
OpenCVE Enrichment