Executive brief
IBM PowerVM Hypervisor, the software responsible for managing virtual machines on IBM Power Systems, contains a vulnerability that could allow a malicious user on a guest operating system to crash the entire physical server. Additionally, an attacker could compromise the memory integrity of the system, potentially leading to unauthorized data modification or system instability. This impact affects the overall availability and reliability of the enterprise server environment.
Technical details
A classic buffer overflow (CWE-120) exists in the IBM PowerVM Hypervisor due to insufficient size checking during the processing of OS hypervisor calls. A local attacker with low privileges on a guest operating system can trigger this vulnerability by issuing a specially crafted hypervisor call. Successful exploitation can lead to a Denial of Service (DoS) by crashing the hypervisor or result in a compromise of system/OS memory integrity. The vulnerability has been addressed in firmware updates FW1110.30, FW1060.72/FW1060.80, and FW950.H2 depending on the specific Power System hardware generation.
Affected products
- IBM PowerVM Hypervisor FW1110.00 - FW1110.20, FW1060.00 - FW1060.71, FW950.00 - FW950.H1
Timeline
- 2026-07-21: disclosed: Initial publication by IBM
- 2026-07-30: advisory: NVD publication date