CVE-2026-19234: This Power System update is being released to address
IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to be executed on the host system. Successful exploitation could result in a confidentiality, integrity, and availability impact to the affected host system.
Other sources
Power Systems Firmware is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to be executed on the host system. Successful exploitation could result in a confidentiality, integrity, and availability impact to the affected host system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Power firmware (host firmware boot process image validation path)to a version that resolves this vulnerability.Patch FW1120.01(1120_190)
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs service access to the service processor. The vulnerability is in the host firmware boot-process image validation path and is exploited by supplying a maliciously crafted code update image.
What systems are affected?
Affected versions are IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80.
What is the potential impact if exploitation succeeds?
Successful exploitation allows arbitrary code execution on the host system. This can affect the confidentiality, integrity, and availability of the affected host system.