CVE-2026-15961: This Power System update is being released to address
IBM PowerVM could allow a local attacker to obtain sensitive information or cause a denial of service due to improper control of format strings.
Other sources
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 could allow a local attacker to obtain sensitive information or cause a denial of service due to improper control of format strings.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM Hypervisor (FW1060 series)to a version that resolves this vulnerability.Fixed in FW1060.81(1060_184) - Upgrade
Upgrade
IBM PowerVM Hypervisor (FW1060 series)to a version that resolves this vulnerability.Fixed in FW1060.81(1060_191) - Upgrade
Upgrade
IBM PowerVM Hypervisor (FW1120 series)to a version that resolves this vulnerability.Fixed in FW1120.01(1120_190)
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires local access, high privileges, and high attack complexity. The available information indicates that remote unauthenticated attackers are not the exposed threat model.
Which PowerVM Hypervisor firmware levels are affected?
Affected levels are FW1120.00; FW1110.00 through FW1110.30; and FW1060.00 through FW1060.80.
What could successful exploitation allow?
A local attacker could obtain sensitive information or cause a denial of service. The vulnerability is caused by improper control of format strings.