CVE-2026-4932

Summary

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.

Affected Software

VendorProductVersion RangeStatus
IBMPowerVM HypervisorFW1110.00 <= FW1110.20affected
IBMPowerVM HypervisorFW1060.00 <= FW1060.71affected

Weaknesses

  • CWE-331: CWE-331 Insufficient Entropy

Workarounds

NOTE: If performing a concurrent upgrade you must reboot the system after updating to the new firmware level to generate fresh TME encryption keys and mitigate this CVE

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References