{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-17097", "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "state": "PUBLISHED", "assignerShortName": "ibm", "dateReserved": "2026-07-24T15:01:11.485Z", "datePublished": "2026-08-19T19:43:31.094Z", "dateUpdated": "2026-08-20T15:57:05.381Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm", "dateUpdated": "2026-08-19T19:43:53.616Z" }, "title": "Power System Improper Validation", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-129", "description": "CWE-129 Improper Validation of Array Index", "type": "CWE" } ] } ], "affected": [ { "vendor": "IBM", "product": "PowerVM Hypervisor", "versions": [ { "status": "affected", "version": "FW1120.00" }, { "status": "affected", "version": "FW1110.00", "lessThanOrEqual": "FW1110.30", "versionType": "semver" }, { "status": "affected", "version": "FW1060.00", "lessThanOrEqual": "FW1060.80", "versionType": "semver" }, { "status": "affected", "version": "FW950.00", "lessThanOrEqual": "FW950.H2", "versionType": "semver" } ], "cpes": [ "cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*" ] } ], "descriptions": [ { "lang": "en", "value": "IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call causing a virtual processor to become permanently unresponsive, requiring a full platform re-IPL to restore normal operation. In some cases this may also cause the guest to inject a small amount of data into hypervisor or partition memory with no attacker control over the target location. Successful exploitation results in an integrity and availability impact to the managed system.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call causing a virtual processor to become permanently unresponsive, requiring a full platform re-IPL to restore normal operation. In some cases this may also cause the guest to inject a small amount of data into hypervisor or partition memory with no attacker control over the target location. Successful exploitation results in an integrity and availability impact to the managed system.

" } ] } ], "references": [ { "url": "https://www.ibm.com/support/pages/node/7283231", "tags": [ "vendor-advisory", "patch" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH", "baseSeverity": "HIGH", "baseScore": 7.3, "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H" } } ], "solutions": [ { "lang": "en", "value": "Customers with the products below should install FW1110.31(1110_134), FW1120.01(1120_167), or newer to remediate this vulnerability.\nPower 11\nIBM Power System E1180 (9080-HEU)\nCustomers with the products below should install FW1110.31(1110_155), FW1120.01(1120_190), or newer to remediate this vulnerability.\nPower 11\nIBM Power System S1122 (9824-22A)\nIBM Power System S1124 (9824-42A)\nIBM Power System S1122s (9824-22B)\nIBM Power System S1114 (9824-41B)\nIBM Power System L1122 (9856-22H)\nIBM Power System L1124 (9856-42H)\nIBM Power System E1150 (9043-MRU)\nCustomers with the products below should install FW1120.01(1120_190), or newer to remediate this vulnerability.\nPower 11\nIBM Power System S1112 (9242-21B, 9242-21T)\n\nCustomers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability.\nPower 10\nIBM Power System E1080 (9080-HEX)\nCustomers with the products below should install FW1060.81(1060_191), or newer to remediate this vulnerability.\nPower 10\nIBM Power System S1022 (9105-22A)\nIBM Power System S1024 (9105-42A)\nIBM Power System S1022s (9105-22B)\nIBM Power System S1014 (9105-41B)\nIBM Power System L1022 (9786-22H)\nIBM Power System L1024 (9786-42H)\nIBM Power System E1050 (9043-MRX)\nIBM Power System S1012 (9028-21B)\n\nCustomers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability.\nPower 9\nIBM Power System S922 (9009-22G)\nIBM Power System H922 (9223-22S)\nIBM Power System S914 (9009-41G)\nIBM Power System S924 (9009-42G)\nIBM Power System H924 (9223-42S)\nIBM Power System E950 (9040-MR9)\nIBM Power System E980 (9080-M9S)\nThe images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

Customers with the products below should install FW1110.31(1110_134), FW1120.01(1120_167), or newer to remediate this vulnerability.
Power 11

  1. IBM Power System E1180 (9080-HEU)

Customers with the products below should install FW1110.31(1110_155), FW1120.01(1120_190), or newer to remediate this vulnerability.
Power 11

  1. IBM Power System S1122 (9824-22A)
  2. IBM Power System S1124 (9824-42A)
  3. IBM Power System S1122s (9824-22B)
  4. IBM Power System S1114 (9824-41B)
  5. IBM Power System L1122 (9856-22H)
  6. IBM Power System L1124 (9856-42H)
  7. IBM Power System E1150 (9043-MRU)

Customers with the products below should install FW1120.01(1120_190), or newer to remediate this vulnerability.

Power 11

  1. IBM Power System S1112 (9242-21B, 9242-21T)


Customers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability.
Power 10

  1. IBM Power System E1080 (9080-HEX)

Customers with the products below should installĀ  FW1060.81(1060_191), or newer to remediate this vulnerability.
Power 10

  1. IBM Power System S1022 (9105-22A)
  2. IBM Power System S1024 (9105-42A)
  3. IBM Power System S1022s (9105-22B)
  4. IBM Power System S1014 (9105-41B)
  5. IBM Power System L1022 (9786-22H)
  6. IBM Power System L1024 (9786-42H)
  7. IBM Power System E1050 (9043-MRX)
  8. IBM Power System S1012 (9028-21B)

Customers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability.
Power 9

  1. IBM Power System S922 (9009-22G)
  2. IBM Power System H922 (9223-22S)
  3. IBM Power System S914 (9009-41G)
  4. IBM Power System S924 (9009-42G)
  5. IBM Power System H924 (9223-42S)
  6. IBM Power System E950 (9040-MR9)
  7. IBM Power System E980 (9080-M9S)

The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/

" } ] } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "id": "CVE-2026-17097", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2026-08-20T15:45:32.700445Z" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-20T15:57:05.381Z" } } ] } }