Impact
This vulnerability arises from improper handling of memory page table configurations, allowing a local attacker to trigger a denial of service. The flaw can lead to a system crash or an unresponsive state, compromising availability of IBM AIX and PowerVM VIOS instances.
Affected Systems
Affected systems include IBM AIX 7.2 and 7.3 (including Service Packs such as AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, and AIX 7.2 TL05 SP13) and IBM PowerVM VIOS 4.1 (covering Fix Packs 4.1.2.20, 4.1.1.30, and 4.1.0.50). These SPs/FPs are cumulative and can be applied atop earlier levels.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity risk of denial of service. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale exploitation yet. The attack requires local access; a privileged local user can manipulate memory page tables to bring the system or virtual machine to an unresponsive state.
OpenCVE Enrichment