CVE-2025-36035
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-14

Last updated on: 2025-12-19

Assigner: IBM Corporation

Description
IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to cause a denial of service by issuing a specially crafted IBM i hypervisor call that would disclose memory contents or consume excessive memory resources.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-14
Last Modified
2025-12-19
Generated
2026-05-06
AI Q&A
2025-09-14
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 27 associated CPEs
Vendor Product Version / Range
ibm powervm_hypervisor From FW950.00 (inc) to FW950.E0 (inc)
ibm power_system_e950_\(9040-mr9\) *
ibm power_system_e980_\(9080-m9s\) *
ibm power_system_h922_\(9223-22h\) *
ibm power_system_h922_\(9223-22s\) *
ibm power_system_h924_\(\(9223-42s\) *
ibm power_system_h924_\(9223-42h\) *
ibm power_system_l922_\(9008-22l\) *
ibm power_system_s914_\(9009-41a\) *
ibm power_system_s914_\(9009-41g\) *
ibm power_system_s922_\(9009-22a\) *
ibm power_system_s922_\(9009-22g\) *
ibm power_system_s924_\(9009-42a\) *
ibm power_system_s924_\(9009-42g\) *
ibm powervm_hypervisor From FW1050.00 (inc) to FW1050.50 (inc)
ibm powervm_hypervisor From FW1060.00 (inc) to FW1060.40 (inc)
ibm power_system_e1080_\(9080-hex\) *
ibm powervm_hypervisor From FW1050.00 (inc) to FW1050.50 (inc)
ibm powervm_hypervisor From FW1060.00 (inc) to FW1060.40 (inc)
ibm power_system_e1050_\(9043-mrx\) *
ibm power_system_l1022_\(9786-22h\) *
ibm power_system_l1024_\(9786-42h\) *
ibm power_system_s1012_\(9028-21b\) *
ibm power_system_s1014_\(9105-41b\) *
ibm power_system_s1022_\(9105-22a\) *
ibm power_system_s1022s_\(9105-22b\) *
ibm power_system_s1024_\(9105-42a\) *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2025-36035 is a vulnerability in the IBM PowerVM hypervisor used in IBM Power Systems. It allows a local privileged user to cause a denial of service (DoS) by issuing a specially crafted IBM i hypervisor call. This can either crash the system or cause limited disclosure of memory contents by improperly making some system memory available. The issue is related to allocation of resources without proper limits or throttling. [1]


How can this vulnerability impact me? :

This vulnerability can impact you by allowing a local privileged user to cause a denial of service, which can crash the system or consume excessive memory resources, potentially disrupting availability. It can also lead to limited disclosure of memory contents, which may expose sensitive information. The impact on confidentiality is low, integrity is not affected, but availability impact is high. [1]


What immediate steps should I take to mitigate this vulnerability?

To mitigate CVE-2025-36035, you should apply the recommended firmware updates for your affected IBM Power Systems. For Power 9 systems, install firmware updates 950.E1 (950_182) or 950.F0 (950_192) or newer. For Power 10 systems, install firmware updates FW1050.51 (1050_095), FW1050.60 (1050_090), FW1060.41 (1060_120), or newer. No other workarounds or mitigations are available. Additionally, subscribe to IBM security notifications for future updates. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart