IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to cause a denial of service by issuing a specially crafted IBM i hypervisor call that would disclose memory contents or consume excessive memory resources.
Fixes

Solution

Customers with the products below should install 950.E1(950_182)/950.F0(950_192) or newer to remediate this vulnerability. Power 9 * IBM Power System L922 (9008-22L) * IBM Power System S922 (9009-22A, 9009-22G) * IBM Power System H922 (9223-22H, 9223-22S) * IBM Power System S914 (9009-41A, 9009-41G) * IBM Power System S924 (9009-42A, 9009-42G) * IBM Power System H924 (9223-42H, 9223-42S) * IBM Power System E950 (9040-MR9) * IBM Power System E980 (9080-M9S) Customers with the products below should install FW1050.51(1050_095)/FW1050.60(1050_090), FW1060.41(1060_120), or newer to remediate this vulnerability. Power 10 * IBM Power System E1080 (9080-HEX)   Customers with the products below should install FW1050.51(1050_113)/FW1050.60(1050_108), FW1060.41(1060_120), or newer to remediate this vulnerability. Power 10 * IBM Power System S1022 (9105-22A) * IBM Power System S1024 (9105-42A) * IBM Power System S1022s (9105-22B) * IBM Power System S1014 (9105-41B) * IBM Power System L1022 (9786-22H) * IBM Power System L1024 (9786-42H) * IBM Power System E1050 (9043-MRX) * IBM Power System S1012 (9028-21B)


Workaround

No workaround given by the vendor.

History

Sun, 14 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
Description IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to cause a denial of service by issuing a specially crafted IBM i hypervisor call that would disclose memory contents or consume excessive memory resources.
Title IBM PowerVM Hypervisor denial of service
First Time appeared Ibm
Ibm power9 System Firmware
Weaknesses CWE-770
CPEs cpe:2.3:o:ibm:power9_system_firmware:fw1050.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power9_system_firmware:fw1050.50:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power9_system_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power9_system_firmware:fw1060.40:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power9_system_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power9_system_firmware:fw950.E0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power9 System Firmware
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-09-14T12:52:48.871Z

Reserved: 2025-04-15T21:16:09.684Z

Link: CVE-2025-36035

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-14T13:15:32.450

Modified: 2025-09-14T13:15:32.450

Link: CVE-2025-36035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.