VYPR
Unrated severityNVD Advisory· Published Feb 14, 2026

efivarfs: fix error propagation in efivar_entry_get()

CVE-2026-23156

Description

In the Linux kernel, the following vulnerability has been resolved:

efivarfs: fix error propagation in efivar_entry_get()

efivar_entry_get() always returns success even if the underlying __efivar_entry_get() fails, masking errors.

This may result in uninitialized heap memory being copied to userspace in the efivarfs_file_read() path.

Fix it by returning the error from __efivar_entry_get().

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.