{"id":"AZL-100467","summary":"CVE-2026-89444 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer\n\nset_attribute() populates the security area of the BIOS attribute request\nbuffer with the current admin password via populate_security_buffer(), then\ndumps the whole request buffer with print_hex_dump_bytes(). This can expose\nthe plaintext admin password in the kernel log.\n\nThe same issue was fixed for the password attribute path by\ncommit d1a196e0a6dc (\"platform/x86: dell-wmi-sysman: Don't hex dump\nplaintext password data\"). Remove the remaining dump from the BIOS\nattribute path.","modified":"2026-09-13T06:06:36Z","published":"2026-09-11T20:19:24Z","upstream":["CVE-2026-89444"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89444"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100467.json"}}],"schema_version":"1.9.0"}