Home

Description

In the Linux kernel, the following vulnerability has been resolved: efivarfs: fix error propagation in efivar_entry_get() efivar_entry_get() always returns success even if the underlying __efivar_entry_get() fails, masking errors. This may result in uninitialized heap memory being copied to userspace in the efivarfs_file_read() path. Fix it by returning the error from __efivar_entry_get().

PUBLISHED Reserved 2026-01-13 | Published 2026-02-14 | Updated 2026-05-11 | Assigner Linux

Product status

Default status
unaffected

2d82e6227ea189c0589e7383a36616ac2a2d248c (git) before 3960f1754664661a970dc9ebbab44ff93a0b4c42
affected

2d82e6227ea189c0589e7383a36616ac2a2d248c (git) before 510a16f1c5c1690b33504052bc13fbc2772c23f8
affected

2d82e6227ea189c0589e7383a36616ac2a2d248c (git) before 89b8ca709eeeabcc11ebba64806677873a2787a8
affected

2d82e6227ea189c0589e7383a36616ac2a2d248c (git) before e4e15a0a4403c96d9898d8398f0640421df9cb16
affected

2d82e6227ea189c0589e7383a36616ac2a2d248c (git) before 4b22ec1685ce1fc0d862dcda3225d852fb107995
affected

Default status
affected

6.0
affected

Any version before 6.0
unaffected

6.1.162 (semver)
unaffected

6.6.123 (semver)
unaffected

6.12.69 (semver)
unaffected

6.18.9 (semver)
unaffected

6.19 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/3960f1754664661a970dc9ebbab44ff93a0b4c42

git.kernel.org/...c/510a16f1c5c1690b33504052bc13fbc2772c23f8

git.kernel.org/...c/89b8ca709eeeabcc11ebba64806677873a2787a8

git.kernel.org/...c/e4e15a0a4403c96d9898d8398f0640421df9cb16

git.kernel.org/...c/4b22ec1685ce1fc0d862dcda3225d852fb107995

cve.org (CVE-2026-23156)

nvd.nist.gov (CVE-2026-23156)

Download JSON