CVE-2026-98191
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: release runtime PM ref on regdomain config failure wlcore_regdomain_config() gets a runtime PM reference before sending the regulatory-domain command. When wlcore_cmd_regdomain_config_locked() fails, the function queues recovery and returns without dropping that reference. Release the reference after handling the command result so both success and failure paths balance the preceding pm_runtime_resume_and_get(). The recovery worker takes a separate runtime PM reference and cannot release the reference held here.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/05b5e297bbf46f92c80da4c2ebe67828ca0d0247
- https://git.kernel.org/stable/c/18eb148105f1af9163f5e9758f0a7bc6ab042423
- https://git.kernel.org/stable/c/3fbaae01bb7847d8b0124a8bbdb3af865e388d53
- https://git.kernel.org/stable/c/7f1f25b2db14683ab75d0d22c00d6a75ba988b83
- https://git.kernel.org/stable/c/85ec6c451fe681ac3135dfa43a519f1404ae63ad
- https://git.kernel.org/stable/c/8a1f3cf89ddcc700e25afe42cfad333059adcc94
- https://git.kernel.org/stable/c/a6bb6ad517a0d4db33a0cac9448e3ae9f4008fb4
- https://git.kernel.org/stable/c/c02352e2b5a241c8da89b5f5f1a0ae4d403120ed
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.