This PowerVM Novalink update is being released to address
Published Jul 17, 2026
7.0
HIGHCVSS 3.1
EPSS 0.13%
Description
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.
Affected products
-
- Version 2.2.02.2.12.2.1.1StatusaffectedConstraints-
- Version 2.3.02.3.0.12.3.12.3.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | PowerVM Novalink | n/a |
|
- 2.2.0
- 2.2.1
- 2.2.1.1
- 2.3.0
- 2.3.0.1
- 2.3.1
- 2.3.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM strongly recommends addressing the vulnerability now by upgrading based on the table below.
ProductVersionRemediationPowerVM Novalink
2.2.1.1
Update to pvm-novalink-2.2.1.1-260708 https://public.dhe.ibm.com/systems/virtualization/Novalink/readme/NovaLink_2.2.1.1_readme.html
or
Update to pvm-novalink-2.3.3-260714 https://public.dhe.ibm.com/systems/virtualization/Novalink/readme/NovaLink_2.3.3_readme.html
PowerVM Novalink
2.3.3
Update to pvm-novalink-2.3.3-260714 https://public.dhe.ibm.com/systems/virtualization/Novalink/readme/NovaLink_2.3.3_readme.html
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45302 Advisory
- https://www.ibm.com/support/pages/node/7280225 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45302 | Advisory | |
| https://www.ibm.com/support/pages/node/7280225 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.