Junglewise Threat Intelligence

CVE-2026-17093: IBM Power Systems Firmware buffer overflow in configuration parsing

CVE-2026-17093 · Severity: high · CVSS 8.2 · Published 2026-08-19

Technologies: IBM Power Systems Firmware. Vendors: IBM.

Executive brief

IBM Power Systems firmware contains a stack-based buffer overflow vulnerability in its host firmware configuration parsing logic. An attacker with service-level administrative access to the system's baseboard management controller (BMC) or service processor can exploit this flaw by supplying malicious configuration data, compromising the firmware boot process and gaining control over the entire system, with potential impact to confidentiality, integrity, and availability.

Technical details

The vulnerability is a stack-based buffer overflow (CWE-121) in the host firmware configuration parsing component of IBM Power Systems firmware. An attacker with service-level access to the BMC/FSP (Flexible Service Processor) can provide specially crafted configuration data that overflows internal buffers during parsing, compromising the host firmware boot stage and all subsequently loaded components. The attack requires elevated (service-level) privileges on the BMC/FSP but no user interaction. Successful exploitation results in complete system compromise affecting confidentiality, integrity, and availability. Patches are available for affected versions across Power 9, Power 10, and Power 11 systems.

Affected products

  • IBM Power Systems Firmware FW1120.00, FW1110.00–FW1110.30, FW1060.00–FW1060.80, FW950.00–FW950.H2, OP940.00–OP940.a1 (Power 9), OP940.00–OP940.81 (Power HMC)

Timeline

  • 2026-08-19: disclosed
  • 2026-08-15: advisory: IBM Security Bulletin initial publication

References

Related threats