CVE-2026-4937

Summary

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.

Affected Software

VendorProductVersion RangeStatus
IBMPowerVM HypervisorFW1110.00 <= FW1110.20affected
IBMPowerVM HypervisorFW1060.00 <= FW1060.71affected
IBMPowerVM HypervisorFW950.00 <= FW950.H2affected

Weaknesses

  • CWE-331: CWE-331 Insufficient Entropy

Workarounds

Fully remediating this CVE requires administrators that have enabled Platform Keystore to take the following actions:

  • Reboot any partitions that have Platform Keystore enabled after updating firmware.
  • Regenerate all cryptographic keys that were generated by Platform Keystore on affected firmware versions, as those keys are considered weak.

References