Database/Firmware, BMC & network fabric

IBM Power Systems Firmware: BMC/FSP root can read and disrupt host processor state across all partitions
Impact
A second flaw in the same BMC/FSP-to-host interface lets an attacker with the service account or root on the service processor reach into and disrupt host processor state. IBM scores it as scope-changed with confidentiality and availability impact on the managed system and every hosted partition — read access to state that belongs to other partitions, and the ability to wedge the machine. Integrity is not claimed here, which distinguishes it from CVE-2026-17429, but the availability half alone means one compromised BMC can drop a whole node and everything scheduled on it.
Who can reach it
Local to the service processor: service account or root on the BMC/FSP. Authenticated; not reachable from a partition or a tenant workload.
What to do
Affected levels are FW1120.00, FW1110.00 through FW1110.30 and FW1060.00 through FW1060.80; IBM's support document (node 7283219) carries the fix levels. Expect a firmware flash with the managed system out of service — batch it with the other Power firmware fixes published the same day rather than opening three windows per machine.
References
Related entries
- TPM 2.0 reference code: leak lets a privileged local user obtain a CA credential for a falsified TPM keyCVE-2026-6726 · TCG TPM 2.0 reference code (attestation credential handling, TCG VRT0010)High
- Linux kernel RDS RDMA path net/rds/rdma.c - rds_rdma_pages: The page-count arithmetic for an RDS RDMA scatter-gatherCVE-2010-3865 · Linux kernel RDS RDMA path net/rds/rdma.c - rds_rdma_pagesHigh
- Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Integer overflow on theCVE-2010-4649 · Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cqHigh
- Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad): The whole drivers/infinibandCVE-2016-4565 · Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad)High
- Linux kernel Soft-RoCE drivers/infiniband/sw/rxe/rxe_mr.c (mem_check_range): The bounds check that is supposed toCVE-2016-8636 · Linux kernel Soft-RoCE drivers/infiniband/sw/rxe/rxe_mr.c (mem_check_range)High
- Intel Server Platform Services (SPS) firmware 4.0 kernelCVE-2017-5709 · Intel Server Platform Services (SPS) firmware 4.0 kernel - the server-chipset variant of ME, Lewisburg PCH / Xeon…High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.