Impact
The flaw permits a local attacker to force a denial of service by causing uncontrolled resource consumption while parsing directory records. This leads to exhaustion of system resources and service interruption for affected IBM AIX and PowerVM VIOS environments. The weakness is an example of uncontrolled resource consumption.
Affected Systems
IBM AIX versions 7.2 and 7.3, specifically AIX 7.2 TL5 SP13, AIX 7.3 TL02 SP5, AIX 7.3 TL03 SP3, and AIX 7.3 TL04 SP2 are impacted. IBM PowerVM VIOS 4.1, including sub‑versions 4.1.0, 4.1.1, and 4.1.2, are affected at all levels listed. The vendor recommends applying the corresponding Service Packs for AIX and Fix Packs for VIOS as noted in the advisory.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate impact. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting no confirmed exploitation yet. The attack vector is local, requiring local access to the affected system; there are no known remote exploitation paths. Even without public exploits, the risk of an internal attacker disrupting services remains significant because resource exhaustion can be triggered through normal or malformed directory operations.
OpenCVE Enrichment