Junglewise Threat Intelligence

CVE-2026-9171: IBM PowerVM Novalink denial of service via memory exhaustion

CVE-2026-9171 · Severity: high · CVSS 7.5 · Published 2026-07-17

Technologies: IBM PowerVM NovaLink. Vendors: IBM.

Executive brief

IBM PowerVM Novalink, a tool used to manage virtualization on IBM Power Systems, is vulnerable to a denial of service attack. By sending a specially crafted request, a remote attacker can force the server to consume excessive memory. This can lead to system instability or a complete service outage, preventing administrators from managing their virtualized environment.

Technical details

IBM PowerVM Novalink is affected by a denial of service vulnerability (CWE-400) originating from its use of IBM WebSphere Application Server Liberty. The flaw allows a remote, unauthenticated attacker to send a specially crafted HTTP request that triggers uncontrolled resource consumption. Specifically, the exploit causes the server to exhaust available memory resources, leading to a denial of service condition. The vulnerability is reachable over the network without user interaction. IBM has released patches for affected versions 2.2.x and 2.3.x to mitigate this issue.

Affected products

  • IBM PowerVM Novalink 2.2.0, 2.2.1, 2.2.1.1, 2.3.0, 2.3.0.1, 2.3.1, 2.3.2

Timeline

  • 2026-07-16: advisory: Initial publication by IBM
  • 2026-07-17: disclosed: NVD publication date

References

Related threats