CVE Vulnerabilities

CVE-2025-36244

External Initialization of Trusted Variables or Data Stores

Published: Sep 16, 2025 | Modified: Oct 17, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.

Weakness

The product initializes critical internal variables or data stores using inputs that can be modified by untrusted actors.

Affected Software

Name Vendor Start Version End Version
Vios Ibm 3.1 (including) 3.1 (including)
Vios Ibm 4.1 (including) 4.1 (including)
Aix Ibm 7.2 (including) 7.2 (including)
Aix Ibm 7.3 (including) 7.3 (including)

Potential Mitigations

References