CVE-2026-18870: This Power System update is being released to address
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
Other sources
PowerVM Hypervisor could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM Hypervisorto a version that resolves this vulnerability.Fixed in 1060.82Patch 1060_189 - Upgrade
Upgrade
IBM PowerVM Hypervisorto a version that resolves this vulnerability.Fixed in 1110.32Patch 1110_138 - Upgrade
Upgrade
IBM PowerVM Hypervisorto a version that resolves this vulnerability.Fixed in 1120.02Patch 1120_171 - Upgrade
Upgrade
IBM PowerVM Hypervisorto a version that resolves this vulnerability.Fixed in 1110.32Patch 1110_160 - Upgrade
Upgrade
IBM PowerVM Hypervisorto a version that resolves this vulnerability.Fixed in 1120.02Patch 1120_195 - Upgrade
Upgrade
IBM PowerVM Hypervisorto a version that resolves this vulnerability.Fixed in 950.H4Patch 950_236 - Upgrade
Upgrade
IBM PowerVM Hypervisorto a version that resolves this vulnerability.Fixed in 1060.82Patch 1060_199
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack vector is adjacent network access. No privileges or user interaction are required.
Which deployments should be treated as affected?
IBM PowerVM Hypervisor deployments running FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, or FW950.00 through FW950.H3 are affected.