CVE-2026-4937 PUBLISHED

Power System Insufficient Entropy

Assigner: ibm
Reserved: 26.03.2026 Published: 19.08.2026 Updated: 19.08.2026

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor IBM
Product PowerVM Hypervisor
Versions
  • affected from FW1110.00 to FW1110.20 (incl.)
  • affected from FW1060.00 to FW1060.71 (incl.)
  • affected from FW950.00 to FW950.H2 (incl.)

Workarounds

Fully remediating this CVE requires administrators that have enabled Platform Keystore to take the following actions:

  • Reboot any partitions that have Platform Keystore enabled after updating firmware.
  • Regenerate all cryptographic keys that were generated by Platform Keystore on affected firmware versions, as those keys are considered weak.

Solutions

Customers with the products below should install FW1110.30(1110_125), FW1120.00(1120_159), or newer to remediate this vulnerability. Power 11

  • IBM Power System E1180 (9080-HEU)

Customers with the products below should install FW1110.30(1110_145), FW1120.00(1120_183), or newer to remediate this vulnerability. Power 11

  • IBM Power System S1122 (9824-22A)
  • IBM Power System S1124 (9824-42A)
  • IBM Power System S1122s (9824-22B)
  • IBM Power System S1114 (9824-41B)
  • IBM Power System L1122 (9856-22H)
  • IBM Power System L1124 (9856-42H)
  • IBM Power System E1150 (9043-MRU)

Customers with the products below should install FW1060.72(1060_171) / FW1060.80(1060_180), or newer to remediate this vulnerability. Power 10

  • IBM Power System E1080 (9080-HEX)

Customers with the products below should install FW1060.72(1060_177) / FW1060.80(1060_185), or newer to remediate this vulnerability. Power 10

  • IBM Power System S1022 (9105-22A)
  • IBM Power System S1024 (9105-42A)
  • IBM Power System S1022s (9105-22B)
  • IBM Power System S1014 (9105-41B)
  • IBM Power System L1022 (9786-22H)
  • IBM Power System L1024 (9786-42H)
  • IBM Power System E1050 (9043-MRX)
  • IBM Power System S1012 (9028-21B)

Customers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability. Power 9

  • IBM Power System S922 (9009-22G)
  • IBM Power System H922 (9223-22S)
  • IBM Power System S914 (9009-41G)
  • IBM Power System S924 (9009-42G)
  • IBM Power System H924 (9223-42S)
  • IBM Power System E950 (9040-MR9)
  • IBM Power System E980 (9080-M9S)

The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/ https://www.ibm.com/support/fixcentral/

References

Problem Types

  • CWE-331 Insufficient Entropy CWE