Inclusion of Sensitive Information in Log Files in Linux kernel - CVE-2026-89444
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the dell-wmi-sysman set_attribute() function when setting BIOS attributes. A local user can cause a BIOS attribute request buffer containing a plaintext administrator password to be logged to disclose sensitive information.