CVE-2026-98191EPSS p7.4%
CVE-2026-98191CVE-2026-98191
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: wlcore: release runtime PM ref on regdomain config failure
wlcore_regdomain_config() gets a runtime PM reference before sending
the regulatory-domain command. When
wlcore_cmd_regdomain_config_locked() fails, the function queues recovery
and returns without dropping that reference.
Release the reference after handling the command result so both success
and failure paths balance the preceding
pm_runtime_resume_and_get(). The recovery worker takes a separate
runtime PM reference and cannot release the reference held here.
Scoring
| EPSS | 0.18% probability of exploitation · percentile 7.4% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |