CVE-2026-17093: Power System Buffer Overflow
IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiality, integrity, and availability impact to the managed system.
Other sources
Power Systems Firmware is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiality, integrity, and availability impact to the managed system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Power Firmwareto a version that resolves this vulnerability.Fixed in FW1060.81(1060_184) - Upgrade
Upgrade
IBM Power Firmwareto a version that resolves this vulnerability.Fixed in FW1060.81(1060_191) - Upgrade
Upgrade
IBM Power Firmwareto a version that resolves this vulnerability.Fixed in FW1120.01(1120_190) - Upgrade
Upgrade
IBM Power Firmwareto a version that resolves this vulnerability.Fixed in FW950.H3(950_230) - Upgrade
Upgrade
IBM Power Firmwareto a version that resolves this vulnerability.Fixed in OP940.82 - Upgrade
Upgrade
IBM Power Firmwareto a version that resolves this vulnerability.Fixed in OP940.a2
Event History
Frequently Asked Questions
Which firmware releases should be checked for exposure?
Affected releases are FW1120.00; FW1110.00 through FW1110.30; FW1060.00 through FW1060.80; FW950.00 through FW950.H2; OP940.00 through OP940.a1 for Power9; and OP940.00 through OP940.81 for Power HMC.
What level of access does an attacker need?
The attacker needs service-level access to the BMC or FSP. They must be able to supply specially crafted host firmware configuration data.
How far can compromise extend if exploitation succeeds?
Successful exploitation can compromise the host firmware boot stage and everything subsequently loaded by it. The resulting impact includes confidentiality, integrity, and availability effects on the managed system.