IBMCVE-2026-4932
IBM PowerVM Hypervisor: attacker could the Transparent Memory Encryption
Medium4.2CVE-2026-4932 · Published Jul 28, 2026 · updated Aug 26, 2026
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| PowerVM Hypervisor Product | >= FW1110.00, <= FW1110.20 | No fix yet |
| >= FW1060.00, <= FW1060.71 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-331
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 28 | IBM WebSphere Application Server: denial of service | High7.5 | No fix yet |
| Jul 28 | IBM Aspera Faspex 5: insufficient session expiration | High8.2 | No fix yet |
| Jul 28 | IBM WebSphere Application Server - Liberty: denial of service | High7.5 | No fix yet |
| Jul 28 | IBM WebSphere Application Server: request smuggling | High8.7 | No fix yet |
| Jul 28 | IBM WebSphere Application Server - Liberty: path traversal | High7.5 | No fix yet |
| Jul 28 | IBM WebSphere Application Server: request smuggling | High8.7 | No fix yet |