VDB
GHSA-qvvw-8673-33g5
GHSA-qvvw-8673-33g5
PUBLISHED
CVSS 5.5 MEDIUM
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data set_new_password() hex dumps the entire buffer, which contains plaintext password data, including current and new passwords. Remove the hex dump to avoid leaking credentials.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploit Intelligence
- CVE-2026-23370.json (github-poc)
- 4593.2.0.yml (github-poc)
- 4628.1.0.yml (github-poc)
- 2026-05-06_426_linux-signed-amd64.yaml (github-poc)
- glcve_test.go (github-poc)
Timeline
- Mar 25, 2026 CVE Published
- Apr 10, 2026 Security Advisory
- Apr 24, 2026 CVE Updated
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-23370 advisory
- https://git.kernel.org/stable/c/0e6115c2f2facaed9593c16ad2e5accd487f5c52 url
- https://git.kernel.org/stable/c/411ba3cd837f7825c0e648e155bc505641f95854 url
- https://git.kernel.org/stable/c/5de34126fb2edf8ab7f25d677b132e92d8bf9ede url
- https://git.kernel.org/stable/c/9bbb420f202834363e1e25435e49db0a385c2232 url
- https://git.kernel.org/stable/c/d1a196e0a6dcddd03748468a0e9e3100790fc85c url
- https://git.kernel.org/stable/c/d78e74adc5cfff7afd9d03b9da8058a7e435f9bc url
- https://git.kernel.org/stable/c/d9e785bd62d2ac23cf29a75dcfea8c8087fd3870 url