CVE-2026-17413
Awaiting Analysis Awaiting Analysis - Queue

IBM PowerVM Hypervisor RTAS Firmware Denial of Service

Vulnerability report for CVE-2026-17413, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS interface. An attacker with administrator-level (root) access to a logical partition can send a specially crafted request to partition firmware, causing the partition to crash and become unavailable. Other partitions on the same managed system are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ibm powervm_hypervisor From FW1120.00 (inc) to FW1120.01 (inc)
ibm powervm_hypervisor From FW1110.00 (inc) to FW1110.31 (inc)
ibm powervm_hypervisor From FW1060.00 (inc) to FW1060.81 (inc)
ibm powervm_hypervisor From FW950.00 (inc) to FW950.H3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects IBM PowerVM Hypervisor firmware versions FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3. It involves a flaw in the RTAS firmware-to-OS interface where an attacker with root access to a logical partition can send a specially crafted request to crash the partition and make it unavailable.

Detection Guidance

Detection requires checking the firmware version of IBM PowerVM Hypervisor. Compare installed versions against affected ranges: FW1120.00-FW1120.01, FW1110.00-FW1110.31, FW1060.00-FW1060.81, FW950.00-FW950.H3. Use IBM tools like HMC or IVM to query firmware versions.

Impact Analysis

If exploited, this vulnerability can cause a partition to crash and become unavailable, disrupting services running on that partition. Since it requires root access to a logical partition, the impact is limited to the affected partition only, with other partitions on the same system remaining unaffected.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it primarily causes partition crashes without data exposure or unauthorized access. However, repeated crashes could disrupt availability of critical systems, potentially affecting service-level agreements or operational reliability required by these standards.

Mitigation Strategies

Install the latest firmware updates provided by IBM: FW1110.32, FW1120.02, FW1060.82, or FW950.H4. No workarounds exist; updates are mandatory. Verify installation via HMC or IVM after applying patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17413. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart