{"id":"CVE-2026-89444","title":"kernel: platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (CVE-2026-89444)","summary":"A flaw was found in the Linux kernel. The `dell-wmi-sysman` driver, responsible for managing Dell WMI (Windows Management Instrumentation) system attributes, incorrectly logs sensitive information. Specifically, when setting a BIOS attribu…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-256","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:49:13+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89444.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89444.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89444"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532198"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89444"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89444"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89444.mbox"},{"url":"https://git.kernel.org/stable/c/22222f92b0a5116eb4aac4be81e7b770adfa32ee"},{"url":"https://git.kernel.org/stable/c/83c80495e45eddf64c6525fb582d8db68f256b71"},{"url":"https://git.kernel.org/stable/c/ceeee18c927958b74a04b92cf084fc496fa21e8b"},{"url":"https://git.kernel.org/stable/c/eb73b9d51490bec4f73ac6efdba5ac535fcfee74"},{"url":"https://git.kernel.org/stable/c/23ba9a18896e198f837ae54be99c8852c41890f7"},{"url":"https://git.kernel.org/stable/c/26f554f9f0fb603f76291c10b1cf979241bd2273"},{"url":"https://git.kernel.org/stable/c/44ec7f1113309a93d0f250bcd49285d21dd1470e"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00205,"epssPercentile":0.10899,"ingestedAt":"2026-09-14T15:23:07.453Z","slug":"CVE-2026-89444","body":"## Overview\n\nA flaw was found in the Linux kernel. The `dell-wmi-sysman` driver, responsible for managing Dell WMI (Windows Management Instrumentation) system attributes, incorrectly logs sensitive information. Specifically, when setting a BIOS attribute, the driver populates a security buffer with the current administrator password and then inadvertently dumps the entire buffer, including the plaintext password, into the kernel log. This can lead to the disclosure of the administrator password to any user with access to the kernel logs.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89444.json)\n\n**kernel: platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":207006,"id":"CVE-2026-89444","ts":1789749736513,"field":"cvss","old":"5.5","new":"7"},{"seq":207005,"id":"CVE-2026-89444","ts":1789749736513,"field":"severity","old":"medium","new":"high"},{"seq":204071,"id":"CVE-2026-89444","ts":1789490231306,"field":"cvss","old":null,"new":"5.5"},{"seq":204070,"id":"CVE-2026-89444","ts":1789490231306,"field":"severity","old":"none","new":"medium"},{"seq":147560,"id":"CVE-2026-89444","ts":1789270211386,"field":"cvss","old":null,"new":"5.5"},{"seq":147559,"id":"CVE-2026-89444","ts":1789270211386,"field":"severity","old":"none","new":"medium"},{"seq":109316,"id":"CVE-2026-89444","ts":1789183731399,"field":"cvss","old":null,"new":"5.5"},{"seq":109315,"id":"CVE-2026-89444","ts":1789183731399,"field":"severity","old":"none","new":"medium"}]}