IBM Product Security Update Advisory (CVE-2026-9171)
IBM Product Security Update Advisory.
A denial-of-service (DoS; an attack that disrupts normal service use) vulnerability, CVE-2026-9171, has been identified in the WebSphere Liberty component of IBM PowerVM NovaLink.
Affected Products and Versions.
- PowerVM NovaLink 2.2.0.
- PowerVM NovaLink 2.2.1.
- PowerVM NovaLink 2.2.1.1.
- PowerVM NovaLink 2.3.0.
- PowerVM Novalink 2.3.0.1.
- PowerVM Novalink 2.3.1.
- PowerVM Novalink 2.3.2.
Mitigation.
- IBM has released security patches to address these vulnerabilities.
- The patched versions provided are pvm-novalink-2.2.1.1-260708 And 2.3.3.
- Users of the affected products should update to the latest version of the Vulnerability Patch following the instructions on the reference site.
Reference.
- Security Bulletin: Vulnerabilities in IBM WebSphere Application (CVE-2026-50645, CVE-2026-9322, CVE-2026-11541, CVE-2026-4410, CVE-2026-9320, CVE-2026-8646, CVE-2026-11806, CVE-2026-9071, CVE-2026-11546, CVE-2026-5516) affects IBM PowerVM Novalink.