cbcvebase.
CVE-2026-23370
published 2026-03-25

CVE-2026-23370: In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data set_new_password()…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
2.6th percentile
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data set_new_password() hex dumps the entire buffer, which contains plaintext password data, including current and new passwords. Remove the hex dump to avoid leaking credentials.

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < 9bbb420f202834363e1e25435e49db0a385c22329bbb420f202834363e1e25435e49db0a385c2232
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < d9e785bd62d2ac23cf29a75dcfea8c8087fd3870d9e785bd62d2ac23cf29a75dcfea8c8087fd3870
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < 411ba3cd837f7825c0e648e155bc505641f95854411ba3cd837f7825c0e648e155bc505641f95854
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < 0e6115c2f2facaed9593c16ad2e5accd487f5c520e6115c2f2facaed9593c16ad2e5accd487f5c52
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < 5de34126fb2edf8ab7f25d677b132e92d8bf9ede5de34126fb2edf8ab7f25d677b132e92d8bf9ede
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < d78e74adc5cfff7afd9d03b9da8058a7e435f9bcd78e74adc5cfff7afd9d03b9da8058a7e435f9bc
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < d1a196e0a6dcddd03748468a0e9e3100790fc85cd1a196e0a6dcddd03748468a0e9e3100790fc85c
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 5.11.0 < 6.1.1676.1.167
linuxlinux_kernel>= 5.11.1 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_msrc4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.