CVE-2026-23156

high

Description

In the Linux kernel, the following vulnerability has been resolved: efivarfs: fix error propagation in efivar_entry_get() efivar_entry_get() always returns success even if the underlying __efivar_entry_get() fails, masking errors. This may result in uninitialized heap memory being copied to userspace in the efivarfs_file_read() path. Fix it by returning the error from __efivar_entry_get().

References

https://git.kernel.org/stable/c/e4e15a0a4403c96d9898d8398f0640421df9cb16

https://git.kernel.org/stable/c/89b8ca709eeeabcc11ebba64806677873a2787a8

https://git.kernel.org/stable/c/510a16f1c5c1690b33504052bc13fbc2772c23f8

https://git.kernel.org/stable/c/4b22ec1685ce1fc0d862dcda3225d852fb107995

https://git.kernel.org/stable/c/3960f1754664661a970dc9ebbab44ff93a0b4c42

Details

Source: Mitre, NVD

Published: 2026-02-14

Updated: 2026-02-14

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 7.1

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High