The OpenPower Foundation maintains a narrowly scoped vulnerability profile centered on skiboot, the open-source firmware bootloader for POWER systems. The recurring weakness pattern reflects numeric-type conversion issues characteristic of low-level firmware code where bit-width and signedness boundaries present structural risks. Current CVE counts, severity breakdown, exploitation status, and detailed disclosures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openpowerfoundation over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36357CRITICAL An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uint16_t "year" value, resulting in a type mismatch that can tr | Oct 22, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openpowerfoundation.
Media articles that mention a CVE ID that affects a product developed by Openpowerfoundation — matched by CVE ID, not by vendor name.