Impact
A stack memory corruption flaw exists in the AIX IPsec ESP decapsulation handler for IBM AIX 7.2, AIX 7.3 and IBM PowerVM VIOS 4.1. An attacker who can trigger this behavior may overwrite kernel stack state, causing a crash of the operating system and resulting in a denial‑of‑service condition. The flaw is a classic heap or stack overflow leading to loss of availability.
Affected Systems
The vulnerability affects IBM AIX versions 7.2 and 7.3 as well as the IBM PowerVM VIOS 4.1 platform. AIX service packs and VIOS fix packs identified by IBM contain the necessary corrections.
Risk and Exploitability
The CVSS score of 6.5 places this change in the medium severity range. The EPSS score is not available, so the likelihood of exploitation cannot be precisely quantified, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the most likely attack vector is remote traffic: a specially crafted IPsec ESP packet sent to the vulnerable host. No public exploitation code has been reported, but the impact of a successful attack is a complete service interruption.
OpenCVE Enrichment