First published: Fri Mar 04 2022(Updated: )
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM VIOS | >=3.1.1<3.1.1.60 | |
IBM VIOS | >=3.1.2<3.1.2.40 | |
IBM VIOS | >=3.1.3<3.1.3.20 | |
IBM AIX | >=7.1.5.0<=7.1.5.36 | |
IBM AIX | >=7.2.4.0<=7.2.4.4 | |
IBM AIX | =7.2.5.0 | |
IBM AIX | =7.2.5.1 | |
IBM AIX | =7.2.5.100 | |
IBM AIX | =7.3.0.0 | |
<=7.1 | ||
<=7.2 | ||
<=7.3 | ||
<=3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38989 is a vulnerability in IBM AIX and VIOS that could allow a non-privileged local user to cause a denial of service.
IBM AIX versions 7.1.0 - 7.1.5.36, 7.2.0 - 7.2.4.4, 7.2.5.0 - 7.2.5.1, 7.2.5.100, and 7.3.0.0 are affected, as well as VIOS versions 3.1.1 - 3.1.1.60, 3.1.2 - 3.1.2.40, and 3.1.3 - 3.1.3.20.
The severity of CVE-2021-38989 is medium with a CVSS score of 6.2.
A non-privileged local user can exploit CVE-2021-38989 by exploiting a vulnerability in the AIX kernel.
Yes, IBM has provided a fix for CVE-2021-38989. Please refer to the IBM support page for more information.