NVRAM Parsing Vulnerability in IBM Power Systems Firmware
CVE-2026-17042

7.3HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-17042?

IBM Power Systems Firmware versions FW950.00 through FW950.H2 and OP940.00 through OP940.a1 (Power9) and OP940.00 - OP940.81 (Power HMC) are susceptible to an NVRAM parsing vulnerability. This flaw allows an attacker with root access to a guest partition on an OpenPOWER system to craft a malicious NVRAM image that can cause the host firmware's boot stage to crash. This results in potential memory corruption and disrupts the integrity and availability of the managed system. Normal operation can only be restored through operator intervention, specifically by clearing the NVRAM via the service processor. It is important to note that only systems running OpenPOWER are affected, while those utilizing PowerVM remain secure.

Affected Version(s)

Power Systems Firmware FW950.00

Power Systems Firmware OP940.00

Power Systems Firmware OP940.00

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.