CVE-2026-16832: Power System Buffer Overflow
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact.
Other sources
Power Systems Firmware is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Power Systems Firmware (FSP management network protocol)to a version that resolves this vulnerability.Fixed in FW1060.81(1060_184)Patch FW1060.81(1060_184) - Upgrade
Upgrade
IBM Power Systems Firmware (FSP management network protocol)to a version that resolves this vulnerability.Fixed in FW1120.01(1120_167)Patch FW1120.01(1120_167) - Upgrade
Upgrade
IBM Power Systems Firmware (FSP management network protocol)to a version that resolves this vulnerability.Fixed in FW1110.31(1110_134)Patch FW1110.31(1110_134) - Upgrade
Upgrade
IBM Power Systems Firmware (FSP management network protocol)to a version that resolves this vulnerability.Fixed in FW950.H3(950_230)Patch FW950.H3(950_230)
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs authenticated HMC administrator access to the FSP management network protocol. The issue is therefore most relevant where HMC administrator credentials or access have been compromised or improperly granted.
What is the potential impact after successful exploitation?
The attacker can execute arbitrary code on the service processor and obtain full control of the managed system. This can affect confidentiality, integrity, and availability.
Which firmware levels are identified as affected?
Affected levels are FW1120.00; FW1110.00 through FW1110.30; FW1060.00 through FW1060.80; and FW950.00 through FW950.H2.