Junglewise Threat Intelligence

CVE-2026-19234: IBM Power Systems Firmware stack-based buffer overflow in boot image validation

CVE-2026-19234 · Severity: high · CVSS 8.2 · Published 2026-08-19

Technologies: IBM Power Systems Firmware. Vendors: IBM.

Executive brief

IBM Power Systems use firmware to manage hardware boot and initialization processes. A vulnerability in the firmware boot image validation allows an attacker with service processor access to upload a malicious firmware update that executes arbitrary code on the affected system. This could lead to complete compromise of the system, affecting data confidentiality, system integrity, and operational availability.

Technical details

This vulnerability is a stack-based buffer overflow (CWE-121) in the host firmware boot process image validation path. An attacker with high-level service processor access can craft a malicious firmware code update image that bypasses validation checks and executes arbitrary code with system privileges. The attack requires local access to the service processor but no user interaction. Successful exploitation results in complete system compromise with impact to confidentiality, integrity, and availability. Patches are available via IBM Fix Central, with different firmware versions (FW1060.81+, FW1110.31+, FW1120.01+) for different Power system models.

Affected products

  • IBM Power Systems Firmware FW1120.00, FW1110.00–FW1110.30, FW1060.00–FW1060.80

Timeline

  • 2026-08-19: disclosed

References

Related threats