Executive brief
IBM Power Systems use firmware to manage hardware boot and initialization processes. A vulnerability in the firmware boot image validation allows an attacker with service processor access to upload a malicious firmware update that executes arbitrary code on the affected system. This could lead to complete compromise of the system, affecting data confidentiality, system integrity, and operational availability.
Technical details
This vulnerability is a stack-based buffer overflow (CWE-121) in the host firmware boot process image validation path. An attacker with high-level service processor access can craft a malicious firmware code update image that bypasses validation checks and executes arbitrary code with system privileges. The attack requires local access to the service processor but no user interaction. Successful exploitation results in complete system compromise with impact to confidentiality, integrity, and availability. Patches are available via IBM Fix Central, with different firmware versions (FW1060.81+, FW1110.31+, FW1120.01+) for different Power system models.
Affected products
- IBM Power Systems Firmware FW1120.00, FW1110.00–FW1110.30, FW1060.00–FW1060.80
Timeline
- 2026-08-19: disclosed