Impact
The firmware flaw lies in NVRAM parsing in IBM Power Systems firmware versions FW950.00 through FW950.H2, OP940.00 through OP940.a1 on Power9, and OP940.00 through OP940.81 on Power Hardware Management Console. An attacker who can gain root privileges on a guest operating system of an OpenPOWER platform can craft a malicious NVRAM image and trigger the host firmware during boot to read beyond expected bounds, causing a crash with possible memory corruption. This results in integrity violations and loss of availability until the system is manually recovered via the service processor. The vulnerability does not affect installations running PowerVM.
Affected Systems
Affected systems include IBM Power System S922, H922, S914, S924, H924, E950, and E980 for firmware FW950.00–FW950.H2; IBM Power System AC922 for firmware OP940.00–OP940.a1; and IBM Power Hardware Management Console for firmware OP940.00–OP940.81. Users should check the specific build numbers on their hardware against the listed firmware versions.
Risk and Exploitability
The CVSS score of 7.3 indicates a moderate to high severity. While the EPSS score is not available and the vulnerability is not yet listed in CISA’s KEV catalog, the risk remains significant because any compromise that yields root on a guest VM can lead to service disruption. Exploitation requires privileged access within the guest but does not need network-level attacker presence, so it is considered a local privilege escalation that abuses the host firmware during boot. Operators should be aware that the crash can persist until NVRAM is cleared by the service processor, which highlights the need for timely remediation.
OpenCVE Enrichment