Description
IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the host firmware boot stage to crash with possible memory corruption. This condition persists until operator intervention — clearing NVRAM via the service processor — to restore normal operation. This vulnerability only affects OpenPOWER systems; systems running PowerVM are not affected. Successful exploitation results in an integrity and availability impact to the managed system.
Published: 2026-08-19
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The firmware flaw lies in NVRAM parsing in IBM Power Systems firmware versions FW950.00 through FW950.H2, OP940.00 through OP940.a1 on Power9, and OP940.00 through OP940.81 on Power Hardware Management Console. An attacker who can gain root privileges on a guest operating system of an OpenPOWER platform can craft a malicious NVRAM image and trigger the host firmware during boot to read beyond expected bounds, causing a crash with possible memory corruption. This results in integrity violations and loss of availability until the system is manually recovered via the service processor. The vulnerability does not affect installations running PowerVM.

Affected Systems

Affected systems include IBM Power System S922, H922, S914, S924, H924, E950, and E980 for firmware FW950.00–FW950.H2; IBM Power System AC922 for firmware OP940.00–OP940.a1; and IBM Power Hardware Management Console for firmware OP940.00–OP940.81. Users should check the specific build numbers on their hardware against the listed firmware versions.

Risk and Exploitability

The CVSS score of 7.3 indicates a moderate to high severity. While the EPSS score is not available and the vulnerability is not yet listed in CISA’s KEV catalog, the risk remains significant because any compromise that yields root on a guest VM can lead to service disruption. Exploitation requires privileged access within the guest but does not need network-level attacker presence, so it is considered a local privilege escalation that abuses the host firmware during boot. Operators should be aware that the crash can persist until NVRAM is cleared by the service processor, which highlights the need for timely remediation.

Generated by OpenCVE AI on August 20, 2026 at 12:30 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability. Power 9 * IBM Power System S922 (9009-22G) * IBM Power System H922 (9223-22S) * IBM Power System S914 (9009-41G) * IBM Power System S924 (9009-42G) * IBM Power System H924 (9223-42S) * IBM Power System E950 (9040-MR9) * IBM Power System E980 (9080-M9S) Customers with the products below should install OP940.a2 or newer to remediate this vulnerability. Power 9 * IBM Power System AC922 (8335-GTH, 8335-GTX) Customers with the products below should install OP940.82 or newer to remediate this vulnerability. Power Hardware Management Console * IBM Power Hardware Management Console (7063-CR2) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/ https://www.ibm.com/support/fixcentral/


OpenCVE Recommended Actions

  • Update to firmware FW950.H3 or newer on affected Power 9 systems to remove the flaw
  • Update to firmware OP940.a2 or newer on IBM Power System AC922 to mitigate the issue
  • Update to firmware OP940.82 or newer on IBM Power Hardware Management Console to apply the fix
  • If an update is not immediately possible, clear the NVRAM configuration via the service processor to restore normal operation until the patch is applied

Generated by OpenCVE AI on August 20, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power Hardware Management Console \(7063-cr2\)
Ibm power Hardware Management Console \(7063-cr2\) Firmware
Ibm power System Ac922 \(8335-gth\)
Ibm power System Ac922 \(8335-gth\) Firmware
Ibm power System Ac922 \(8335-gtx\)
Ibm power System Ac922 \(8335-gtx\) Firmware
Ibm power System E950 \(9040-mr9\)
Ibm power System E950 \(9040-mr9\) Firmware
Ibm power System E980 \(9080-m9s\)
Ibm power System E980 \(9080-m9s\) Firmware
Ibm power System H922 \(9223-22s\)
Ibm power System H922 \(9223-22s\) Firmware
Ibm power System H924 \(9223-42s\)
Ibm power System H924 \(9223-42s\) Firmware
Ibm power System S914 \(9009-41g\)
Ibm power System S914 \(9009-41g\) Firmware
Ibm power System S922 \(9009-22g\)
Ibm power System S922 \(9009-22g\) Firmware
Ibm power System S924 \(9009-42g\)
Ibm power System S924 \(9009-42g\) Firmware
CPEs cpe:2.3:h:ibm:power_hardware_management_console_\(7063-cr2\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_ac922_\(8335-gth\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_ac922_\(8335-gtx\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e950_\(9040-mr9\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e980_\(9080-m9s\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h922_\(9223-22s\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h924_\(9223-42s\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s914_\(9009-41g\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s922_\(9009-22g\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s924_\(9009-42g\):-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_hardware_management_console_\(7063-cr2\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_ac922_\(8335-gth\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_ac922_\(8335-gtx\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e950_\(9040-mr9\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e980_\(9080-m9s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_h922_\(9223-22s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_h924_\(9223-42s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s914_\(9009-41g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s922_\(9009-22g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s924_\(9009-42g\)_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ibm power Hardware Management Console \(7063-cr2\)
Ibm power Hardware Management Console \(7063-cr2\) Firmware
Ibm power System Ac922 \(8335-gth\)
Ibm power System Ac922 \(8335-gth\) Firmware
Ibm power System Ac922 \(8335-gtx\)
Ibm power System Ac922 \(8335-gtx\) Firmware
Ibm power System E950 \(9040-mr9\)
Ibm power System E950 \(9040-mr9\) Firmware
Ibm power System E980 \(9080-m9s\)
Ibm power System E980 \(9080-m9s\) Firmware
Ibm power System H922 \(9223-22s\)
Ibm power System H922 \(9223-22s\) Firmware
Ibm power System H924 \(9223-42s\)
Ibm power System H924 \(9223-42s\) Firmware
Ibm power System S914 \(9009-41g\)
Ibm power System S914 \(9009-41g\) Firmware
Ibm power System S922 \(9009-22g\)
Ibm power System S922 \(9009-22g\) Firmware
Ibm power System S924 \(9009-42g\)
Ibm power System S924 \(9009-42g\) Firmware

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power Systems Firmware
CPEs cpe:2.3:o:ibm:power_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.a1:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:op940.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:op940.a1:*:*:*:*:*:*:*
Vendors & Products Ibm power Firmware
Ibm power Systems Firmware

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the host firmware boot stage to crash with possible memory corruption. This condition persists until operator intervention — clearing NVRAM via the service processor — to restore normal operation. This vulnerability only affects OpenPOWER systems; systems running PowerVM are not affected. Successful exploitation results in an integrity and availability impact to the managed system.
Title Power System Out-of-bounds Read
First Time appeared Ibm
Ibm power Firmware
Weaknesses CWE-125
CPEs cpe:2.3:o:ibm:power_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.a1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Firmware
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H'}


Subscriptions

Ibm Power Hardware Management Console \(7063-cr2\) Power Hardware Management Console \(7063-cr2\) Firmware Power System Ac922 \(8335-gth\) Power System Ac922 \(8335-gth\) Firmware Power System Ac922 \(8335-gtx\) Power System Ac922 \(8335-gtx\) Firmware Power System E950 \(9040-mr9\) Power System E950 \(9040-mr9\) Firmware Power System E980 \(9080-m9s\) Power System E980 \(9080-m9s\) Firmware Power System H922 \(9223-22s\) Power System H922 \(9223-22s\) Firmware Power System H924 \(9223-42s\) Power System H924 \(9223-42s\) Firmware Power System S914 \(9009-41g\) Power System S914 \(9009-41g\) Firmware Power System S922 \(9009-22g\) Power System S922 \(9009-22g\) Firmware Power System S924 \(9009-42g\) Power System S924 \(9009-42g\) Firmware Power Systems Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-19T19:46:38.034Z

Reserved: 2026-07-24T12:55:35.930Z

Link: CVE-2026-17042

cve-icon Vulnrichment

Updated: 2026-08-19T19:24:33.411Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T20:17:12.127

Modified: 2026-08-25T13:14:08.000

Link: CVE-2026-17042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T12:45:03Z

Weaknesses