CVE-2026-19321: Power System Integer Overflow
IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system.
Other sources
Power Systems Firmware is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What level of access is required to exploit this issue?
An attacker needs service access to the service processor and must be able to submit a carefully crafted command.
How can I determine whether a system is affected?
Check the installed IBM Power Firmware level. The affected levels are FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80.
What could successful exploitation expose or disrupt?
The crafted command could expose hardware-register contents that should not be accessible to the service processor. The stated consequences are limited confidentiality or availability impacts to the affected host system.