Database/Firmware, BMC & network fabric

IBM Power Systems Firmware: crafted configuration data from the BMC/FSP compromises the host boot stage
Impact
Host firmware mishandles configuration data supplied through the service processor, so an attacker with service-level BMC/FSP access can compromise the host firmware boot stage and, with it, everything loaded afterwards — hypervisor, partitions and workloads. Because the compromise lands at boot, it survives reinstalling partitions and is not something a host-side agent can detect. Affected levels reach back through FW950 and the OP940 Power9 and Power HMC streams. Recovery for a system you believe was hit is a firmware rebuild, not a redeploy.
Who can reach it
An attacker with authenticated service-level access to the BMC/FSP. That means management-network reach and valid service credentials; no interaction from a host user is needed.
What to do
Apply the fixed IBM firmware for the affected FW1120, FW1110, FW1060, FW950 and OP940 levels per the advisory, as a firmware flash on the managed system (and on the HMC for the OP940 Power HMC stream). Because the flaw is in the boot path, a system suspected of prior compromise should be re-flashed rather than only updated. No mitigation short of updating is stated in the record.
References
Related entries
- IBM Power Systems Firmware: service processor mailbox allows code execution in host firmware runtimeCVE-2026-17100 · IBM Power Systems Firmware (service processor mailbox interface)High
- IBM Power Systems Firmware: crafted BMC command executes arbitrary code on the host systemCVE-2026-17494 · IBM Power Systems Firmware (BMC-to-host command interface)High
- IBM Power Systems Firmware: crafted code update image passes boot validation and executes on the hostCVE-2026-19234 · IBM Power Systems Firmware (host boot image validation path)High
- NVIDIA DGX Spark firmware: out-of-bounds write reachable by a privileged local attackerCVE-2026-24262 · NVIDIA DGX Spark system firmwareHigh
- NVIDIA DGX Spark firmware: NULL pointer dereference reachable by a privileged local attackerCVE-2026-24263 · NVIDIA DGX Spark system firmwareHigh
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): After a transmit-queue error triggers driver recovery, theCVE-2026-43466 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.