CVE-2026-98191: wifi: wlcore: release runtime PM ref on regdomain config failure
In the Linux kernel, the following vulnerability has been resolved:
wifi: wlcore: release runtime PM ref on regdomain config failure
wlcoreregdomainconfig() gets a runtime PM reference before sending the regulatory-domain command. When wlcorecmdregdomainconfiglocked() fails, the function queues recovery and returns without dropping that reference.
Release the reference after handling the command result so both success and failure paths balance the preceding pmruntimeresumeandget(). The recovery worker takes a separate runtime PM reference and cannot release the reference held here.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
In wlcore_regdomain_config(), release the runtime PM reference obtained by pm_runtime_resume_and_get() after handling the regulatory-domain command result, including the failure path when wlcore_cmd_regdomain_config_locked() queues recovery.