CVE-2026-0012
published 2026-03-02CVE-2026-0012: In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local…
PriorityP427medium6.2CVSS 3.1
AVLACLPRNUINSUCHINAN
EPSS
0.10%
1.1th percentile
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| linux | linux_kernel | >= 5.12.0 < 6.12.67 | 6.12.67 |
| linux | linux_kernel | >= 6.13.0 < 6.18.7 | 6.18.7 |
| platform | frameworks_base | >= 14:0 < 14:2026-03-01 | 14:2026-03-01 |
| platform | frameworks_base | >= 15:0 < 15:2026-03-01 | 15:2026-03-01 |
| platform | frameworks_base | >= 16-qpr2-next:0 < 16-qpr2-next:2026-03-01 | 16-qpr2-next:2026-03-01 |
| platform | frameworks_base | >= 16:0 < 16:2026-03-01 | 16:2026-03-01 |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6cq5-q29c-9g34: In setHideSensitive of ExpandableNotificationRow
ghsa_unreviewed·2026-03-02
CVE-2026-0012 [MEDIUM] CWE-284 GHSA-6cq5-q29c-9g34: In setHideSensitive of ExpandableNotificationRow
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2026-0012: In setHideSensitive of ExpandableNotificationRow
osv·2026-03-01
CVE-2026-0012 CVE-2026-0012: In setHideSensitive of ExpandableNotificationRow
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv
osv·2026-01-31
CVE-2026-23035 net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv
net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv
mlx5e_priv is an unstable structure that can be memset(0) if profile
attaching fails.
Pass netdev to mlx5e_destroy_netdev() to guarantee it will work on a
valid netdev.
On mlx5e_remove: Check validity of priv->profile, before attempting
to cleanup any resources that might be not there.
This fixes a kernel oops in mlx5e_remove when switchdev mode fails due
to change profile failure.
$ devlink dev eswitch set pci/0000:00:03.0 mode switchdev
Error: mlx5_core: Failed setting eswitch to offloads.
dmesg:
workqueue: Failed to create a rescuer kthread for wq "mlx5e": -EINTR
mlx5_core 0012:03:00.1: ml
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0012 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.2
CVE-2026-0012 [MEDIUM] CVE-2026-0012 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0012 :
NixOS vulnerability analysis and mitigation
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Source : NVD
## 6.2
Score
Published March 2, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
android
Sources
NVD
Nix Severity MEDIUM No Fix Added at: Mar 04, 2026
## Get a CVE risk assessment
Get a prioritized
Wiz
CVE-2026-23035 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-23035 CVE-2026-23035 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23035 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv
mlx5e_priv is an unstable structure that can be memset(0) if profile
attaching fails.
Pass netdev to mlx5e_destroy_netdev() to guarantee it will work on a
valid netdev.
On mlx5e_remove: Check validity of priv->profile, before attempting
to cleanup any resources that might be not there.
This fixes a kernel oops in mlx5e_remove when switchdev mode fails due
to change profile failure.
$ devlink dev eswitch set pci/0000:00:03.0 mode switchdev
Error: mlx5_core: Failed setting eswitch to offloads.
dmesg:
workqueue: Failed to create a rescuer kthread for wq "mlx5e": -EINTR
mlx5_core 0012:03
2026-03-02
Published