7.3

CVE-2026-17042

Power System Out-of-bounds Read

IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the host firmware boot stage to crash with possible memory corruption. This condition persists until operator intervention — clearing NVRAM via the service processor — to restore normal operation. This vulnerability only affects OpenPOWER systems; systems running PowerVM are not affected. Successful exploitation results in an integrity and availability impact to the managed system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Power System Ac922 (8335-gth) Firmware Version >= op940 < op940.a2
Ibm ≫ Power System Ac922 (8335-gtx) Firmware Version >= op940 < op940.a2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.012
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
IBM 7.3 2 4.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://www.ibm.com/support/pages/node/7283240
Vendor Advisory