Microsoft Security Response Center guidance
Vendor revision: Oct 7, 2026Release Notes
Vulnerability intelligence
CVE-2026-98191. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: release runtime PM ref on regdomain config failure wlcore_regdomain_config() gets a runtime PM reference before sending the regulatory-domain command. When wlcore_cmd_regdomain_config_locked() fails, the function queues recovery and returns without dropping that reference. Release the reference after handling the command result so both success and failure paths balance the preceding pm_runtime_resume_and_get(). The recovery worker takes a separate runtime PM reference and cannot release the reference held here.
Source: NVD