Description
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity.
Published: 2026-07-30
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM PowerVM Hypervisor firmware versions from FW1110.00 to FW1110.20, FW1060.00 to FW1060.71, and FW950.00 to FW950.H1 contain a buffer overflow that can be triggered by a carefully crafted hypervisor call originating from a guest operating system. The flaw stems from an improper bounds check performed during a buffer copy, resulting in a crash of the hypervisor or corruption of operating system memory integrity. If an attacker succeeds in poisoning guest memory, the damaged hypervisor might allow execution of arbitrary code within the hypervisor environment or enable a denial‑of‑service to the entire host.

Affected Systems

Affected systems are IBM PowerVM Hypervisor firmware running on Power 9, Power 10, and Power 11 Power Systems. Firmware releases from FW1110.00 to FW1110.20 are vulnerable on Power 11 models such as the E1180, S1122, S1124, S1114, L1122, L1124, and E1150. Firmware releases from FW1060.00 to FW1060.71 affect Power 10 models such as the E1080, S1022, S1024, S1014, L1022, L1024, E1050, and S1012. Firmware releases from FW950.00 to FW950.H1 impact Power 9 models such as the L922, S922, H922, S914, S924, H924, E950, and E980. The precise hardware model list is provided in the IBM advisory.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1% suggests a relatively low probability of current exploitation in the general population. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires the attacker to control or influence a guest operating system to issue a malicious hypervisor call, indicating that the likely attack vector is internal or local to the virtual machine. When exploited, the hypervisor may crash or allow memory corruption that could lead to elevated privileges or denial of service for the host system.

Generated by OpenCVE AI on August 3, 2026 at 10:41 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1110.30(1110_125), or newer to remediate this vulnerability. Power 11 * IBM Power System E1180 (9080-HEU) Customers with the products below should install FW1110.30(1110_145), or newer to remediate this vulnerability. Power 11 * IBM Power System S1122 (9824-22A) * IBM Power System S1124 (9824-42A) * IBM Power System S1122s (9824-22B) * IBM Power System S1114 (9824-41B) * IBM Power System L1122 (9856-22H) * IBM Power System L1124 (9856-42H) * IBM Power System E1150 (9043-MRU) Customers with the products below should install FW1060.72(1060_171)/FW1060.80(1060_180), or newer to remediate this vulnerability. Power 10 * IBM Power System E1080 (9080-HEX) Customers with the products below should install  FW1060.72(1060_177)/FW1060.80(1060_185),  or newer to remediate this vulnerability. Power 10 * IBM Power System S1022 (9105-22A) * IBM Power System S1024 (9105-42A) * IBM Power System S1022s (9105-22B) * IBM Power System S1014 (9105-41B) * IBM Power System L1022 (9786-22H) * IBM Power System L1024 (9786-42H) * IBM Power System E1050 (9043-MRX) * IBM Power System S1012 (9028-21B) Customers with the products below should install FW950.H2(950_222) or newer to remediate this concern. Power 9 * IBM Power System L922 (9008-22L) * IBM Power System S922 (9009-22A, 9009-22G) * IBM Power System H922 (9223-22H, 9223-22S) * IBM Power System S914 (9009-41A, 9009-41G) * IBM Power System S924 (9009-42A, 9009-42G) * IBM Power System H924 (9223-42H, 9223-42S) * IBM Power System E950 (9040-MR9) * IBM Power System E980 (9080-M9S)


OpenCVE Recommended Actions

  • Apply the latest firmware upgrade for the affected PowerVM Hypervisor: install FW1110.30(1110_145) or newer on Power 11 systems, install FW1060.72(1060_171) or newer on Power 10 systems, and install FW950.H2(950_222) or newer on Power 9 systems.
  • If an upgrade is not immediately possible, isolate the hypervisor from untrusted traffic, enforce network segmentation, and enable hypervisor‑level monitoring to detect abnormal memory usage or crashes.
  • Review and adjust guest operating system configurations to avoid legacy hypervisor calls that could trigger the buffer overflow, and restrict guest processes to minimal privileges.

Generated by OpenCVE AI on August 3, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity.
Title Power System update in Buffer Copy
First Time appeared Ibm
Ibm powervm Hypervisor
Weaknesses CWE-120
CPEs cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw950.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw950.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw950.h1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw950.h1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm powervm Hypervisor
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Ibm Powervm Hypervisor
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T17:35:20.927Z

Reserved: 2026-06-10T14:14:43.892Z

Link: CVE-2026-11885

cve-icon Vulnrichment

Updated: 2026-07-30T17:32:35.460Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-30T17:16:27.760

Modified: 2026-07-30T19:17:03.763

Link: CVE-2026-11885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:45:03Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')