IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the host firmware boot stage to crash with possible memory corruption. This condition persists until operator intervention — clearing NVRAM via the service processor — to restore normal operation. This vulnerability only affects OpenPOWER systems; systems running PowerVM are not affected. Successful exploitation results in an integrity and availability impact to the managed system.

Project Subscriptions

Vendors Products
Power Systems Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

Customers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability. Power 9 * IBM Power System S922 (9009-22G) * IBM Power System H922 (9223-22S) * IBM Power System S914 (9009-41G) * IBM Power System S924 (9009-42G) * IBM Power System H924 (9223-42S) * IBM Power System E950 (9040-MR9) * IBM Power System E980 (9080-M9S) Customers with the products below should install OP940.a2 or newer to remediate this vulnerability. Power 9 * IBM Power System AC922 (8335-GTH, 8335-GTX) Customers with the products below should install OP940.82 or newer to remediate this vulnerability. Power Hardware Management Console * IBM Power Hardware Management Console (7063-CR2) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/ https://www.ibm.com/support/fixcentral/


Workaround

No workaround given by the vendor.

History

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power Systems Firmware
CPEs cpe:2.3:o:ibm:power_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.a1:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:op940.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:op940.a1:*:*:*:*:*:*:*
Vendors & Products Ibm power Firmware
Ibm power Systems Firmware

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the host firmware boot stage to crash with possible memory corruption. This condition persists until operator intervention — clearing NVRAM via the service processor — to restore normal operation. This vulnerability only affects OpenPOWER systems; systems running PowerVM are not affected. Successful exploitation results in an integrity and availability impact to the managed system.
Title Power System Out-of-bounds Read
First Time appeared Ibm
Ibm power Firmware
Weaknesses CWE-125
CPEs cpe:2.3:o:ibm:power_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.a1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Firmware
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-19T19:46:38.034Z

Reserved: 2026-07-24T12:55:35.930Z

Link: CVE-2026-17042

cve-icon Vulnrichment

Updated: 2026-08-19T19:24:33.411Z

cve-icon NVD

Status : Received

Published: 2026-08-19T20:17:12.127

Modified: 2026-08-19T20:17:12.127

Link: CVE-2026-17042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses