CVE-2026-22978: Linux Kernel
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: wifi: avoid kernel-infoleak from struct iw_point struct iw_point has a 32bit hole on 64bit arches. struct iw_point { void __user *pointer; /* Pointer to the data (in user space) */ __u16 length; /* number of fields or size in bytes */ __u16 flags; /* Optional params */ }; Make sure to zero the structure to avoid disclosing 32bits of kernel data to user space.
Affected products
- Linux Linux Kernel: from 2.6.27, before 5.10.248 (fixed in 5.10.248); from 5.11, before 5.15.198 (fixed in 5.15.198); from 5.16, before 6.1.161 (fixed in 6.1.161); from 6.2, before 6.6.121 (fixed in 6.6.121); from 6.7, before 6.12.66 (fixed in 6.12.66); from 6.13, before 6.18.6 (fixed in 6.18.6); …
Published 2026-01-23. Last modified 2026-06-17.