Boletines de Vulnerabilidades

CVE-2026-23370

   
Software afectado DELL
 
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data

set_new_password() hex dumps the entire buffer, which contains plaintext
password data, including current and new passwords. Remove the hex dump
to avoid leaking credentials.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-23370