cbcvebase.
CVE-2026-23156
published 2026-02-14

CVE-2026-23156: In the Linux kernel, the following vulnerability has been resolved: efivarfs: fix error propagation in efivar_entry_get() efivar_entry_get() always returns…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved: efivarfs: fix error propagation in efivar_entry_get() efivar_entry_get() always returns success even if the underlying __efivar_entry_get() fails, masking errors. This may result in uninitialized heap memory being copied to userspace in the efivarfs_file_read() path. Fix it by returning the error from __efivar_entry_get().

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 2d82e6227ea189c0589e7383a36616ac2a2d248c < 3960f1754664661a970dc9ebbab44ff93a0b4c423960f1754664661a970dc9ebbab44ff93a0b4c42
linuxlinux>= 2d82e6227ea189c0589e7383a36616ac2a2d248c < 510a16f1c5c1690b33504052bc13fbc2772c23f8510a16f1c5c1690b33504052bc13fbc2772c23f8
linuxlinux>= 2d82e6227ea189c0589e7383a36616ac2a2d248c < 89b8ca709eeeabcc11ebba64806677873a2787a889b8ca709eeeabcc11ebba64806677873a2787a8
linuxlinux>= 2d82e6227ea189c0589e7383a36616ac2a2d248c < e4e15a0a4403c96d9898d8398f0640421df9cb16e4e15a0a4403c96d9898d8398f0640421df9cb16
linuxlinux>= 2d82e6227ea189c0589e7383a36616ac2a2d248c < 4b22ec1685ce1fc0d862dcda3225d852fb1079954b22ec1685ce1fc0d862dcda3225d852fb107995
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.9-16.18.9-1
linuxlinux_kernel>= 6.0 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.18.96.18.9
linuxlinux_kernel>= 6.2 < 6.6.1236.6.123
linuxlinux_kernel>= 6.7 < 6.12.696.12.69
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fde-6.17
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.