CVE Vulnerabilities

CVE-2025-36194

Improper Access Control for Register Interface

Published: Feb 02, 2026 | Modified: Feb 19, 2026
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations.

Weakness

The product uses memory-mapped I/O registers that act as an interface to hardware functionality from software, but there is improper access control to those registers.

Affected Software

NameVendorStart VersionEnd Version
Powervm_hypervisorIbmfw950.00 (including)fw950.00 (including)
Powervm_hypervisorIbmfw950.10 (including)fw950.10 (including)
Powervm_hypervisorIbmfw950.11 (including)fw950.11 (including)
Powervm_hypervisorIbmfw950.20 (including)fw950.20 (including)
Powervm_hypervisorIbmfw950.30 (including)fw950.30 (including)
Powervm_hypervisorIbmfw950.40 (including)fw950.40 (including)
Powervm_hypervisorIbmfw950.50 (including)fw950.50 (including)
Powervm_hypervisorIbmfw950.60 (including)fw950.60 (including)
Powervm_hypervisorIbmfw950.70 (including)fw950.70 (including)
Powervm_hypervisorIbmfw950.71 (including)fw950.71 (including)
Powervm_hypervisorIbmfw950.80 (including)fw950.80 (including)
Powervm_hypervisorIbmfw950.90 (including)fw950.90 (including)
Powervm_hypervisorIbmfw950.a0 (including)fw950.a0 (including)
Powervm_hypervisorIbmfw950.b0 (including)fw950.b0 (including)
Powervm_hypervisorIbmfw950.c0 (including)fw950.c0 (including)
Powervm_hypervisorIbmfw950.c1 (including)fw950.c1 (including)
Powervm_hypervisorIbmfw950.c2 (including)fw950.c2 (including)
Powervm_hypervisorIbmfw950.d0 (including)fw950.d0 (including)
Powervm_hypervisorIbmfw950.d1 (including)fw950.d1 (including)
Powervm_hypervisorIbmfw950.e0 (including)fw950.e0 (including)
Powervm_hypervisorIbmfw950.e1 (including)fw950.e1 (including)
Powervm_hypervisorIbmfw950.f0 (including)fw950.f0 (including)
Powervm_hypervisorIbmfw1060.00 (including)fw1060.00 (including)
Powervm_hypervisorIbmfw1060.10 (including)fw1060.10 (including)
Powervm_hypervisorIbmfw1060.12 (including)fw1060.12 (including)
Powervm_hypervisorIbmfw1060.20 (including)fw1060.20 (including)
Powervm_hypervisorIbmfw1060.21 (including)fw1060.21 (including)
Powervm_hypervisorIbmfw1060.40 (including)fw1060.40 (including)
Powervm_hypervisorIbmfw1060.41 (including)fw1060.41 (including)
Powervm_hypervisorIbmfw1060.50 (including)fw1060.50 (including)
Powervm_hypervisorIbmfw1060.51 (including)fw1060.51 (including)
Powervm_hypervisorIbmfw1110.00 (including)fw1110.00 (including)
Powervm_hypervisorIbmfw1110.01 (including)fw1110.01 (including)
Powervm_hypervisorIbmfw1110.03 (including)fw1110.03 (including)

Extended Description

Software commonly accesses peripherals in a System-on-Chip (SoC) or other device through a memory-mapped register interface. Malicious software could tamper with any security-critical hardware data that is accessible directly or indirectly through the register interface, which could lead to a loss of confidentiality and integrity.

Potential Mitigations

References