CVE-2026-89444EPSS p10.4%
CVE-2026-89444CVE-2026-89444
Description
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
set_attribute() populates the security area of the BIOS attribute request
buffer with the current admin password via populate_security_buffer(), then
dumps the whole request buffer with print_hex_dump_bytes(). This can expose
the plaintext admin password in the kernel log.
The same issue was fixed for the password attribute path by
commit d1a196e0a6dc ("platform/x86: dell-wmi-sysman: Don't hex dump
plaintext password data"). Remove the remaining dump from the BIOS
attribute path.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 10.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-14 |