CVE-2026-98191

medium

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: release runtime PM ref on regdomain config failure wlcore_regdomain_config() gets a runtime PM reference before sending the regulatory-domain command. When wlcore_cmd_regdomain_config_locked() fails, the function queues recovery and returns without dropping that reference. Release the reference after handling the command result so both success and failure paths balance the preceding pm_runtime_resume_and_get(). The recovery worker takes a separate runtime PM reference and cannot release the reference held here.

References

https://git.kernel.org/stable/c/c02352e2b5a241c8da89b5f5f1a0ae4d403120ed

https://git.kernel.org/stable/c/a6bb6ad517a0d4db33a0cac9448e3ae9f4008fb4

https://git.kernel.org/stable/c/8a1f3cf89ddcc700e25afe42cfad333059adcc94

https://git.kernel.org/stable/c/85ec6c451fe681ac3135dfa43a519f1404ae63ad

https://git.kernel.org/stable/c/7f1f25b2db14683ab75d0d22c00d6a75ba988b83

https://git.kernel.org/stable/c/3fbaae01bb7847d8b0124a8bbdb3af865e388d53

https://git.kernel.org/stable/c/18eb148105f1af9163f5e9758f0a7bc6ab042423

https://git.kernel.org/stable/c/05b5e297bbf46f92c80da4c2ebe67828ca0d0247

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93119

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00184