Zum Inhalt springen
CodeAuditAgent

CVE-2026-16707

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system.

Schwachstellenklasse

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system.

Betroffene Produkte

  • ibm power_system_s1122_\(9824-22a\)_firmware
  • ibm power_system_s1122_\(9824-22a\)
  • ibm power_system_s1124_\(9824-42a\)_firmware
  • ibm power_system_s1124_\(9824-42a\)
  • ibm power_system_s1122s_\(9824-22b\)_firmware
  • ibm power_system_s1122s_\(9824-22b\)
  • ibm power_system_s1114_\(9824-41b\)_firmware
  • ibm power_system_s1114_\(9824-41b\)

Quellen

Finden Sie die Schwachstelle, bevor es ein Angreifer tut.

Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.