Impact
IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1 are affected by an integer underflow that can be triggered remotely, leading to a denial of service and potentially allowing disclosure of sensitive data. The flaw is a classic unsigned integer underflow (CWE‑190) that, when exploited, can cause system components to behave unexpectedly, resulting in service interruption or leakage of protected information.
Affected Systems
IBM AIX versions 7.2 through 7.3 remain vulnerable unless updated to Service Pack TL04 SP2 or higher, with specific cumulative SPs listed: SP13 for 7.2, SP2 for AIX 7.3 TL04, SP3 for AIX 7.3 TL03, and SP5 for AIX 7.3 TL02. The corresponding IBM PowerVM VIOS Fix Packs are 4.1.0.50, 4.1.1.30, and 4.1.2.20. IBM recommends applying these levels via Fix Central, including cumulative patches that cover prior vulnerabilities.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity, while the EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote interaction with the affected operating system; an attacker can potentially cause a denial of service or retrieve sensitive data. The default remediation path involves deploying the appropriate service or fix pack, performing a reboot or live update, and following post‑update procedures for Postgres migration and nimsh secure protocol updates.
OpenCVE Enrichment