Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98191— wifi: wlcore: release runtime PM ref on regdomain config failure

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: 无线网卡:wlcore 驱动:在 regdomain 配置失败时释放运行时电源管理(PM)引用 函数在发送域管制(regulatory-domain)命令之前会获取一个运行时 PM 引用。当 调用失败时,该函数会启动恢复机制并返回,但未能释放此前获取的 PM 引用。 本修复确保在处理后命令结果时释放该引用,从而使成功和失败两种路径都能正确平衡前面对 的调用。需要注意的是,恢复工作线程会获取独立的运行时 PM 引用,且无法释放此处持有的引用。

AI Predicted 4.3 Difficulty: Trivial EPSS 0.18% · P7

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8< 85ec6c451fe681ac3135dfa43a519f1404ae63ad affected
fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8< 3fbaae01bb7847d8b0124a8bbdb3af865e388d53 affected
fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8< c02352e2b5a241c8da89b5f5f1a0ae4d403120ed affected
fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8< 05b5e297bbf46f92c80da4c2ebe67828ca0d0247 affected
fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8< 18eb148105f1af9163f5e9758f0a7bc6ab042423 affected
fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8< 7f1f25b2db14683ab75d0d22c00d6a75ba988b83 affected
fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8< a6bb6ad517a0d4db33a0cac9448e3ae9f4008fb4 affected
fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8< 8a1f3cf89ddcc700e25afe42cfad333059adcc94 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98191

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: wlcore: release runtime PM ref on regdomain config failure
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: release runtime PM ref on regdomain config failure wlcore_regdomain_config() gets a runtime PM reference before sending the regulatory-domain command. When wlcore_cmd_regdomain_config_locked() fails, the function queues recovery and returns without dropping that reference. Release the reference after handling the command result so both success and failure paths balance the preceding pm_runtime_resume_and_get(). The recovery worker takes a separate runtime PM reference and cannot release the reference held here.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux fa2648a34e73fb7a17fd0a82e0335a9451d8f5c8 ~ 85ec6c451fe681ac3135dfa43a519f1404ae63ad -
Linux Linux 4.19 -

II. Public POCs for CVE-2026-98191

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98191

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98191 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98191

No comments yet


Leave a comment