Executive brief
A security issue has been identified in the firmware of IBM Power10 and Power11 systems that weakens the encryption used to protect data stored in the system's memory. If an attacker has physical access to the server hardware, they may be able to bypass these protections and read sensitive information directly from the memory. To fully resolve this issue, administrators must update the system firmware and perform a full system reboot to generate new, secure encryption keys.
Technical details
A vulnerability in the IBM PowerVM Hypervisor firmware (FW1110 and FW1060 streams) results in insufficient entropy during the generation of AES keys for Transparent Memory Encryption (TME). This weakness in cryptographic strength could allow an attacker with physical access to the TME hardware to decrypt data residing in system memory. The attack requires physical access and is considered high complexity due to the technical requirements of intercepting and decrypting TME-protected streams. Remediation requires updating to patched firmware levels (e.g., FW1110.30 or FW1060.72/80) and performing a mandatory system reboot to cycle the encryption keys.
Affected products
- IBM PowerVM Hypervisor FW1110.00 - FW1110.20
- IBM PowerVM Hypervisor FW1060.00 - FW1060.71
Timeline
- 2026-07-21: disclosed: Initial publication by IBM
- 2026-07-28: advisory: NVD publication date