SB2026032575 - Exposure of Private Information ('Privacy Violation') in Linux kernel dell dell-wmi-sysman driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Exposure of Private Information ('Privacy Violation') (CVE-ID: CVE-2026-23370)
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper output neutralization in the dell-wmi-sysman driver when handling password data. A local user can access kernel logs to disclose sensitive information.
The vulnerability specifically involves the logging of plaintext passwords via a hex dump in the set_new_password() function, which could expose current and new passwords.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0e6115c2f2facaed9593c16ad2e5accd487f5c52
- https://git.kernel.org/stable/c/411ba3cd837f7825c0e648e155bc505641f95854
- https://git.kernel.org/stable/c/5de34126fb2edf8ab7f25d677b132e92d8bf9ede
- https://git.kernel.org/stable/c/d1a196e0a6dcddd03748468a0e9e3100790fc85c
- https://git.kernel.org/stable/c/d78e74adc5cfff7afd9d03b9da8058a7e435f9bc
- https://git.kernel.org/stable/c/d9e785bd62d2ac23cf29a75dcfea8c8087fd3870