CVE-2026-17494: Power System Buffer Overflow
IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
Other sources
Power Systems Firmware is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Power Systems Firmwareto a version that resolves this vulnerability.Fixed in FW1110.31(1110_134) - Upgrade
Upgrade
IBM Power Systems Firmwareto a version that resolves this vulnerability.Fixed in FW1120.01(1120_167) - Upgrade
Upgrade
IBM Power Systems Firmwareto a version that resolves this vulnerability.Fixed in FW1110.31(1110_155) - Upgrade
Upgrade
IBM Power Systems Firmwareto a version that resolves this vulnerability.Fixed in FW1120.01(1120_190)
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Systems running IBM Power Firmware FW1120.00 or FW1110.00 through FW1110.30 are affected when an attacker has service access to the BMC.
What level of access does an attacker need?
The attacker requires service access to the BMC and must send a specially crafted command through the BMC-to-host interface. The issue is locally exploitable and does not require user interaction.
What is the potential impact if exploitation succeeds?
An attacker can execute arbitrary code on the host system and obtain full control of the host and all hosted partitions. This can affect confidentiality, integrity, and availability.