CVE Vulnerabilities

CVE-2025-0986

Improper Handling of Highly Compressed Data (Data Amplification)

Published: Mar 28, 2025 | Modified: Aug 18, 2025
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certain Linux processor combability mode configurations, to cause undetected data loss or errors when performing gzip compression using HW acceleration.

Weakness

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Affected Software

Name Vendor Start Version End Version
Powervm_hypervisor Ibm fw1050.00 (including) fw1050.30 (including)
Powervm_hypervisor Ibm fw1060.00 (including) fw1060.20 (including)

References