PT-2022-24786 · Ibm · Aix+2

Published

2022-12-14

·

Updated

2022-12-31

·

CVE-2022-39164

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM AIX versions 7.1 through 7.3 VIOS version 3.1
Description The issue allows a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. This can be achieved by exploiting the vulnerability in the AIX pfcdd kernel extension.
Recommendations For IBM AIX versions 7.1 through 7.3, consider applying configuration changes to restrict access to the kernel extension until a patch is available. For VIOS version 3.1, restrict access to the vulnerable kernel extension to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2022-39164

Affected Products

Aix
Ibm Aix
Vios