-
CVE-2026-89444
- EPSS 0.2%
- Veröffentlicht 11.09.2026 19:43:12
- Zuletzt bearbeitet 14.09.2026 13:19:01
- Erkennungen
platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
set_attribute() populates the security area of the BIOS attribute request
buffer with the current admin password via populate_security_buffer(), then
dumps the whole request buffer with print_hex_dump_bytes(). This can expose
the plaintext admin password in the kernel log.
The same issue was fixed for the password attribute path by
commit d1a196e0a6dc ("platform/x86: dell-wmi-sysman: Don't hex dump
plaintext password data"). Remove the remaining dump from the BIOS
attribute path.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
e8a60aa7404bfef37705da5607c97737073ac38d
Version <
23ba9a18896e198f837ae54be99c8852c41890f7
Status
affected
Version
e8a60aa7404bfef37705da5607c97737073ac38d
Version <
26f554f9f0fb603f76291c10b1cf979241bd2273
Status
affected
Version
e8a60aa7404bfef37705da5607c97737073ac38d
Version <
44ec7f1113309a93d0f250bcd49285d21dd1470e
Status
affected
Version
e8a60aa7404bfef37705da5607c97737073ac38d
Version <
ceeee18c927958b74a04b92cf084fc496fa21e8b
Status
affected
Version
e8a60aa7404bfef37705da5607c97737073ac38d
Version <
22222f92b0a5116eb4aac4be81e7b770adfa32ee
Status
affected
Version
e8a60aa7404bfef37705da5607c97737073ac38d
Version <
eb73b9d51490bec4f73ac6efdba5ac535fcfee74
Status
affected
Version
e8a60aa7404bfef37705da5607c97737073ac38d
Version <
83c80495e45eddf64c6525fb582d8db68f256b71
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.11
Status
affected
Version
0
Version <
5.11
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.1 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/ceeee18c927958b74a04b92cf084fc496fa21e8b
https://git.kernel.org/stable/c/22222f92b0a5116eb4aac4be81e7b770adfa32ee
https://git.kernel.org/stable/c/eb73b9d51490bec4f73ac6efdba5ac535fcfee74
https://git.kernel.org/stable/c/83c80495e45eddf64c6525fb582d8db68f256b71
https://git.kernel.org/stable/c/23ba9a18896e198f837ae54be99c8852c41890f7
https://git.kernel.org/stable/c/26f554f9f0fb603f76291c10b1cf979241bd2273
https://git.kernel.org/stable/c/44ec7f1113309a93d0f250bcd49285d21dd1470e