CVE-2026-98191
Received
Received - Intake
WiFi Runtime PM Reference Leak in Linux Kernel
Vulnerability report for CVE-2026-98191, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: wlcore: release runtime PM ref on regdomain config failure
wlcore_regdomain_config() gets a runtime PM reference before sending
the regulatory-domain command. When
wlcore_cmd_regdomain_config_locked() fails, the function queues recovery
and returns without dropping that reference.
Release the reference after handling the command result so both success
and failure paths balance the preceding
pm_runtime_resume_and_get(). The recovery worker takes a separate
runtime PM reference and cannot release the reference held here.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8 |
| Linux | Linux | fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8 |
| Linux | Linux | fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8 |
| Linux | Linux | fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8 |
| Linux | Linux | fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8 |
| Linux | Linux | fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8 |
| Linux | Linux | fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8 |
| Linux | Linux | fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8 |
| Linux | Linux | 4.19 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |