CVE-2026-23156

HIGH

Linux Kernel 6.0.0-6.18.8 - Information Disclosure via efivarfs Error Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: efivarfs: fix error propagation in efivar_entry_get() efivar_entry_get() always returns success even if the underlying __efivar_entry_get() fails, masking errors. This may result in uninitialized heap memory being copied to userspace in the efivarfs_file_read() path. Fix it by returning the error from __efivar_entry_get().

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 4.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (18)
linux/Kernel 6.0.0 - 6.1.162linux
linux/Kernel 6.13.0 - 6.18.9linux
linux/Kernel 6.2.0 - 6.6.123linux
linux/Kernel 6.7.0 - 6.12.69linux
Linux/Linux < 6.0
Linux/Linux 2d82e6227ea189c0589e7383a36616ac2a2d248c - 3960f1754664661a970dc9ebbab44ff93a0b4c42
Linux/Linux 2d82e6227ea189c0589e7383a36616ac2a2d248c - 4b22ec1685ce1fc0d862dcda3225d852fb107995
Linux/Linux 2d82e6227ea189c0589e7383a36616ac2a2d248c - 510a16f1c5c1690b33504052bc13fbc2772c23f8
Linux/Linux 2d82e6227ea189c0589e7383a36616ac2a2d248c - 89b8ca709eeeabcc11ebba64806677873a2787a8
Linux/Linux 2d82e6227ea189c0589e7383a36616ac2a2d248c - e4e15a0a4403c96d9898d8398f0640421df9cb16
... and 8 more
Published Feb 14, 2026
Tracked Since Feb 18, 2026