CVE-2026-98191

Source
https://cve.org/CVERecord?id=CVE-2026-98191
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98191.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98191
Downstream
Published
2026-10-06T08:44:32Z
Modified
2026-10-08T02:52:52Z
Summary
wifi: wlcore: release runtime PM ref on regdomain config failure
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: wlcore: release runtime PM ref on regdomain config failure

wlcore_regdomain_config() gets a runtime PM reference before sending the regulatory-domain command. When wlcore_cmd_regdomain_config_locked() fails, the function queues recovery and returns without dropping that reference.

Release the reference after handling the command result so both success and failure paths balance the preceding pm_runtime_resume_and_get(). The recovery worker takes a separate runtime PM reference and cannot release the reference held here.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98191.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8
Fixed
85ec6c451fe681ac3135dfa43a519f1404ae63ad
Fixed
3fbaae01bb7847d8b0124a8bbdb3af865e388d53
Fixed
c02352e2b5a241c8da89b5f5f1a0ae4d403120ed
Fixed
05b5e297bbf46f92c80da4c2ebe67828ca0d0247
Fixed
18eb148105f1af9163f5e9758f0a7bc6ab042423
Fixed
7f1f25b2db14683ab75d0d22c00d6a75ba988b83
Fixed
a6bb6ad517a0d4db33a0cac9448e3ae9f4008fb4
Fixed
8a1f3cf89ddcc700e25afe42cfad333059adcc94

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98191.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98191.json"