CVE-2026-18857: This Power System update is being released to address
IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface. The host system can cause the BMC firmware management service to crash or allow a limited amount of BMC internal memory to be read, resulting in a confidentiality and availability impact to the managed system.
Other sources
Power Systems Firmware is affected by a vulnerability in the BMC firmware management interface. The host system can cause the BMC firmware management service to crash or allow a limited amount of BMC internal memory to be read, resulting in a confidentiality and availability impact to the managed system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Power Systems Firmwareto a version that resolves this vulnerability.Fixed in FW1060.82Patch 1060_199 - Upgrade
Upgrade
IBM Power Systems Firmwareto a version that resolves this vulnerability.Fixed in FW1120.02Patch 1120_195 - Upgrade
Upgrade
IBM Power Systems Firmwareto a version that resolves this vulnerability.Fixed in FW1110.32Patch 1110_160
Event History
Frequently Asked Questions
What level of access is required to exploit this issue?
The CVSS vector indicates local attack access and high privileges are required. No user interaction is required.
Which firmware releases should be checked?
Affected releases are IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81.
What could exploitation allow on an affected system?
A host system can crash the BMC firmware management service or read a limited amount of BMC internal memory. The stated impacts are confidentiality and availability effects on the managed system.