No analysis available yet.
Vendor Solution
Customers with the products below should install FW1110.30(1110_125), or newer and reboot the system to remediate this vulnerability. Power 11 * IBM Power System E1180 (9080-HEU) Customers with the products below should install FW1110.30(1110_145), or newer and reboot the system to remediate this vulnerability. Power 11 * IBM Power System S1122 (9824-22A) * IBM Power System S1124 (9824-42A) * IBM Power System S1122s (9824-22B) * IBM Power System S1114 (9824-41B) * IBM Power System L1122 (9856-22H) * IBM Power System L1124 (9856-42H) * IBM Power System E1150 (9043-MRU) Customers with the products below should install FW1060.72(1060_171)/FW1060.80(1060_180), or newer and reboot the system to remediate this vulnerability. Power 10 * IBM Power System E1080 (9080-HEX) Customers with the products below should install FW1060.72(1060_177)/FW1060.80(1060_185), or newer and reboot the system to remediate this vulnerability. Power 10 * IBM Power System S1022 (9105-22A) * IBM Power System S1024 (9105-42A) * IBM Power System S1022s (9105-22B) * IBM Power System S1014 (9105-41B) * IBM Power System L1022 (9786-22H) * IBM Power System L1024 (9786-42H) * IBM Power System E1050 (9043-MRX) * IBM Power System S1012 (9028-21B)
Vendor Workaround
NOTE: If performing a concurrent upgrade you must reboot the system after updating to the new firmware level to generate fresh TME encryption keys and mitigate this CVE
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7280632 |
|
Tue, 28 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy. | |
| Title | This Power System update is being released to address Insufficient Entropy | |
| First Time appeared |
Ibm
Ibm powervm Hypervisor |
|
| Weaknesses | CWE-331 | |
| CPEs | cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm powervm Hypervisor |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-07-28T18:46:57.145Z
Reserved: 2026-03-26T19:43:02.211Z
Link: CVE-2026-4932
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T19:30:16Z
-
CWE-331
Insufficient Entropy