GHSA-GPVF-H969-VP49

Vulnerability from github – Published: 2026-10-06 09:31 – Updated: 2026-10-06 09:31
VLAI
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: wlcore: release runtime PM ref on regdomain config failure

wlcore_regdomain_config() gets a runtime PM reference before sending the regulatory-domain command. When wlcore_cmd_regdomain_config_locked() fails, the function queues recovery and returns without dropping that reference.

Release the reference after handling the command result so both success and failure paths balance the preceding pm_runtime_resume_and_get(). The recovery worker takes a separate runtime PM reference and cannot release the reference held here.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-98191"
  ],
  "database_specific": {
    "cwe_ids": [],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-10-06T09:18:04Z",
    "severity": null
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wlcore: release runtime PM ref on regdomain config failure\n\nwlcore_regdomain_config() gets a runtime PM reference before sending\nthe regulatory-domain command. When\nwlcore_cmd_regdomain_config_locked() fails, the function queues recovery\nand returns without dropping that reference.\n\nRelease the reference after handling the command result so both success\nand failure paths balance the preceding\npm_runtime_resume_and_get(). The recovery worker takes a separate\nruntime PM reference and cannot release the reference held here.",
  "id": "GHSA-gpvf-h969-vp49",
  "modified": "2026-10-06T09:31:30Z",
  "published": "2026-10-06T09:31:29Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98191"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/05b5e297bbf46f92c80da4c2ebe67828ca0d0247"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/18eb148105f1af9163f5e9758f0a7bc6ab042423"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/3fbaae01bb7847d8b0124a8bbdb3af865e388d53"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/7f1f25b2db14683ab75d0d22c00d6a75ba988b83"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/85ec6c451fe681ac3135dfa43a519f1404ae63ad"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8a1f3cf89ddcc700e25afe42cfad333059adcc94"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a6bb6ad517a0d4db33a0cac9448e3ae9f4008fb4"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c02352e2b5a241c8da89b5f5f1a0ae4d403120ed"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…