Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: wlcore: release runtime PM ref on regdomain config failure

wlcore_regdomain_config() gets a runtime PM reference before sending
the regulatory-domain command. When
wlcore_cmd_regdomain_config_locked() fails, the function queues recovery
and returns without dropping that reference.

Release the reference after handling the command result so both success
and failure paths balance the preceding
pm_runtime_resume_and_get(). The recovery worker takes a separate
runtime PM reference and cannot release the reference held here.
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via use‑after‑free
Action: Immediate Patch
AI Analysis

Impact

A bug in the Linux kernel’s wireless driver wlcore causes a runtime power‑management reference to be released only on success, while the failure path retains the reference after scheduling recovery. If an attacker triggers the failure path repeatedly, the reference count can become unsynchronized, potentially leading to a use‑after‑free situation and a kernel crash. The primary impact is a denial of service by destabilizing the operating system, rather than leaking data or elevating privileges.

Affected Systems

All Linux kernel builds that include wlcore without the patch are affected. The exact kernel versions are not specified in the advisory, so any distribution using the stock kernel should assess whether the wlcore driver is present and unpatched.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable, making the likelihood of exploitation uncertain. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely a local or remote user able to send malicious regulatory‑domain commands to a wireless interface, as the bug is triggered during wlcore_regdomain_config_locked processing. Because the defect involves kernel reference counting, successful exploitation would require privilege escalation or local access to the wireless interface.

Generated by OpenCVE AI on October 6, 2026 at 11:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that includes the wlcore_regdomain_config fix, which balances the PM reference in both success and failure paths

Generated by OpenCVE AI on October 6, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: release runtime PM ref on regdomain config failure wlcore_regdomain_config() gets a runtime PM reference before sending the regulatory-domain command. When wlcore_cmd_regdomain_config_locked() fails, the function queues recovery and returns without dropping that reference. Release the reference after handling the command result so both success and failure paths balance the preceding pm_runtime_resume_and_get(). The recovery worker takes a separate runtime PM reference and cannot release the reference held here.
Title wifi: wlcore: release runtime PM ref on regdomain config failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:44:32.240Z

Reserved: 2026-09-25T10:25:14.323Z

Link: CVE-2026-98191

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:04.377

Modified: 2026-10-06T09:18:04.377

Link: CVE-2026-98191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:30:07Z

Weaknesses