CVE-2026-17097
Analyzed Analyzed - Analysis Complete

PowerVM Hypervisor Call Denial of Service

Vulnerability report for CVE-2026-17097, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-25

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call causing a virtual processor to become permanently unresponsive, requiring a full platform re-IPL to restore normal operation. In some cases this may also cause the guest to inject a small amount of data into hypervisor or partition memory with no attacker control over the target location. Successful exploitation results in an integrity and availability impact to the managed system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-25
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 34 associated CPEs
Vendor Product Version / Range
ibm power_system_s1122_(9824-22a)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1122_(9824-22a)_firmware fw1120.00
ibm power_system_s1124_(9824-42a)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1124_(9824-42a)_firmware fw1120.00
ibm power_system_s1122s_(9824-22b)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1122s_(9824-22b)_firmware fw1120.00
ibm power_system_s1114_(9824-41b)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1114_(9824-41b)_firmware fw1120.00
ibm power_system_l1122_(9856-22h)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_l1122_(9856-22h)_firmware fw1120.00
ibm power_system_l1124_(9856-42h)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_l1124_(9856-42h)_firmware fw1120.00
ibm power_system_e1150_(9043-mru)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_e1150_(9043-mru)_firmware fw1120.00
ibm power_system_s1112_(9242-21b)_firmware fw1120.00
ibm power_system_s1112_(9242-21t)_firmware fw1120.00
ibm power_system_e1080_(9080-hex)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1022_(9105-22a)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1024_(9105-42a)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1022s_(9105-22b)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1014_(9105-41b)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_l1022_(9786-22h)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_l1024_(9786-42h)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_e1050_(9043-mrx)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1012_(9028-21b)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_e1180_(9080-heu)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_e1180_(9080-heu)_firmware fw1120.00
ibm power_system_s922_(9009-22g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_h922_(9223-22s)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_s914_(9009-41g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_s924_(9009-42g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_h924_(9223-42s)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_e950_(9040-mr9)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_e980_(9080-m9s)_firmware From fw950.00 (inc) to fw950.h3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-17097 is a flaw in IBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. An attacker with root access to a guest partition can send a malicious hypervisor call that may crash a virtual processor, requiring a full system restart to recover. In rare cases, it might also allow uncontrolled data injection into hypervisor or partition memory.

Detection Guidance

Detection primarily involves checking firmware versions against affected ranges. Use IBM's firmware management tools or commands like 'lsmcode -r' on AIX/Linux to list installed firmware versions. Compare against affected versions: FW1120.00, FW1110.00–FW1110.30, FW1060.00–FW1060.80, FW950.00–FW950.H2.

Impact Analysis

If exploited, this vulnerability can cause system downtime as a virtual processor becomes unresponsive, requiring a full platform re-IPL. It may also lead to data corruption or unauthorized memory access, affecting system integrity. The impact is limited to systems running affected PowerVM firmware versions.

Compliance Impact

This vulnerability primarily impacts integrity and availability of the managed system, which could lead to non-compliance with regulations like GDPR or HIPAA that require data integrity and system availability. Uncontrolled data injection into memory may also violate confidentiality requirements under these standards.

Mitigation Strategies

Install the latest firmware updates provided by IBM for your Power Systems model. Check IBM Fix Central for patches specific to Power 9, Power 10, or Power 11 systems. No workarounds exist; firmware updates are required to resolve the issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17097. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart