Junglewise Threat Intelligence

CVE-2026-17494: IBM Power Systems Firmware stack-based buffer overflow in BMC interface

CVE-2026-17494 · Severity: high · CVSS 8.2 · Published 2026-08-19

Technologies: IBM Power Systems Firmware. Vendors: IBM.

Executive brief

IBM Power Systems firmware contains a stack-based buffer overflow vulnerability in the BMC (Baseboard Management Controller) interface. An attacker with service-level access to the BMC can execute arbitrary code on the host system, gaining complete control over all hosted applications and partitions. This results in full compromise of confidentiality, integrity, and availability of the entire system.

Technical details

A stack-based buffer overflow (CWE-121) exists in the BMC-to-host interface of affected IBM Power Systems firmware versions. The vulnerability is triggered when an attacker with BMC service access sends a specially crafted command to the interface, causing a buffer overflow that permits arbitrary code execution on the host system. The attack requires high privileges (service/administrative access to the BMC) but no user interaction. Successful exploitation grants the attacker complete control of the host OS and all virtualized partitions running on it. Patches are available: FW1110.31 or newer, or FW1120.01 or newer, depending on the specific system model.

Affected products

  • IBM Power Systems Firmware FW1110.00 through FW1110.30, FW1120.00

Timeline

  • 2026-08-15: disclosed
  • 2026-08-19: patched: Patches released: FW1110.31 and FW1120.01

References

Related threats