CVE-2026-4937
5.3
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Summary
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | PowerVM Hypervisor | FW1110.00 <= FW1110.20 | affected |
| IBM | PowerVM Hypervisor | FW1060.00 <= FW1060.71 | affected |
| IBM | PowerVM Hypervisor | FW950.00 <= FW950.H2 | affected |
Weaknesses
- CWE-331: CWE-331 Insufficient Entropy
Workarounds
Fully remediating this CVE requires administrators that have enabled Platform Keystore to take the following actions:
- Reboot any partitions that have Platform Keystore enabled after updating firmware.
- Regenerate all cryptographic keys that were generated by Platform Keystore on affected firmware versions, as those keys are considered weak.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.