CVE-2014-3074: IBM Aix

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.

Affected products

  • IBM Aix: version 6.1 only; version 7.1 only
  • IBM Vios: version 2.2.0.10 only; version 2.2.0.11 only; version 2.2.0.12 only; version 2.2.0.13 only; version 2.2.1.0 only; version 2.2.1.1 only; …

Published 2014-07-02. Last modified 2026-06-17.