First published: Mon May 06 2024(Updated: )
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | <=7.2 | |
IBM AIX | <=7.3 | |
IBM Virtual I/O Server (VIOS) | <=3.1 | |
IBM Virtual I/O Server (VIOS) | <=4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27273 is rated as a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2024-27273, you should apply the latest security updates provided by IBM for AIX 7.2, 7.3, and VIOS 3.1, 4.1.
CVE-2024-27273 affects IBM AIX versions up to 7.3 and IBM VIOS versions up to 4.1.
CVE-2024-27273 is a privilege escalation vulnerability in the Unix domain datagram socket implementation.
Yes, CVE-2024-27273 can potentially affect production environments that use vulnerable versions of IBM AIX and VIOS, leading to security risks.