Impact
The vulnerability is a pointer validation flaw in the AIX Virtual SCSI (vSCSI) initiator driver. Exploitation may trigger a denial‑of‑service condition, allow an attacker to gain elevated privileges, or lead to full compromise of the client LPAR’s kernel. This weakness is captured by CWE‑822, indicating improper pointer validation within the driver code.
Affected Systems
Affected vendors are IBM for AIX and PowerVM VIOS. For AIX, the flaw is present in versions 7.2 and 7.3 until the following service packs: 7.3 TL04 SP2, 7.3 TL03 SP3, 7.3 TL02 SP5, and 7.2 TL05 SP13. For PowerVM VIOS, the flaw exists in levels 4.1.0 through 4.1.2 until the fix packs: 4.1.0.50, 4.1.1.30, and 4.1.2.20. The service packs and fix packs are cumulative and can be applied to any earlier level.
Risk and Exploitability
The CVSS score of 8.2 classifies this flaw as a high severity vulnerability. Because EPSS is presently unavailable, the estimated exploitation probability is indeterminate, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the exploitation would most likely occur through crafted virtual SCSI requests originating from a guest or via a remote VM that interacts with the host’s vSCSI driver, allowing local or remote privilege escalation and denial of service. Full compromise of the client kernel would enable an attacker to execute arbitrary code with kernel privileges.
OpenCVE Enrichment