Impact
A buffer overflow in the host firmware configuration parsing of IBM PowerVM Hypervisor firmware exposes a memory corruption vulnerability (CWE‑121). When exploited, the flaw can crash the host firmware boot stack, potentially corrupting memory during system initialization and disrupting the operation of the managed system. The impact is loss of functionality and possible integrity compromise of firmware state.
Affected Systems
Affected platforms include IBM PowerVM Hypervisor firmware versions FW1060.00 to FW1060.80, FW1110.00 to FW1110.30, and FW1120.00. The issue is relevant to IBM Power System models such as E1180, S1122, S1124, S1122s, S1114, L1122, L1124, E1150, S1112, E1080, S1022, S1024, S1022s, S1014, L1022, L1024, E1050, and S1012 across Power 10 and Power 11 families.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.3, indicating a high severity. While EPSS data is not available and the flaw is not yet listed in the CISA KEV catalog, the attack vector requires authenticated service‑processor access, making exploitation dependent on credential compromise or insider abuse. Once executed, the crash can cause loss of availability and potential integrity damage during system startup.
OpenCVE Enrichment