Weakness in IBM PowerVM Hypervisor KeyStore and TPM Firmware
CVE-2026-4936
5.1MEDIUM
What is CVE-2026-4936?
IBM's PowerVM Hypervisor Platform KeyStore (PKS) and certain versions of its virtual TPM firmware have a vulnerability due to the use of persistent storage key seeds that result in an AES key with diminished strength. This flaw enables an attacker with sufficient access to the service processor or Hardware Management Console (HMC) to potentially derive the encryption key, leading to unauthorized data access.
Affected Version(s)
PowerVM Hypervisor FW1110.00
PowerVM Hypervisor FW1060.00
PowerVM Hypervisor FW950.00