Denial of Service Vulnerability in IBM PowerVM Hypervisor
CVE-2026-17413

5.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
24 September 2026

What is CVE-2026-17413?

IBM PowerVM Hypervisor is impacted by a vulnerability in the RTAS firmware-to-OS interface. An authenticated attacker with root access to a logical partition can initiate a specially crafted request to the partition firmware. This action can lead to a crash of the targeted partition, rendering it unavailable. However, it is important to note that other partitions on the same managed system remain unaffected by this incident.

Affected Version(s)

PowerVM Hypervisor FW1120.00

PowerVM Hypervisor FW1110.00

PowerVM Hypervisor FW1060.00

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.