KernelScan.io

HIGH Introduced in 2.6.14

libipw MichaelMic OOB

CVE-2026-98193

CVSS 8.1 / 10.0 KernelScan AI

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

01

In the Linux kernel, the following vulnerability has been resolved: wifi: libipw: reject TKIP frames without a full MIC libipw_michael_mic_verify() assumes that an skb contains an eight-byte Michael MIC. A short TKIP frame makes the unsigned payload length wrap, causing michael_mic() to read past the skb. Check that the MIC is present before verifying it, and use the existing MICHAEL_MIC_LEN constant for all MIC lengths in the verifier.

02

Engine v0.7.0

Risk summary

An attacker within WiFi range of a device using the Intel ipw2x00 wireless driver with TKIP encryption can send a deliberately short TKIP frame to trigger an out-of-bounds read in the kernel. This can leak kernel memory contents or crash the system. No authentication or privileges are required—only wireless proximity to the target.

Affecteddrivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c (libipw TKIP crypto)

Vulnerability analysis

The TKIP Michael MIC verification routine in the Intel ipw2x00 WiFi driver assumes every received TKIP frame contains an eight-byte MIC trailer. When a frame shorter than the header plus eight bytes arrives, the unsigned payload-length calculation underflows to a very large value, causing the MIC computation function to read far past the end of the packet buffer—leaking kernel memory or triggering a page fault panic. The fix adds a length check that rejects frames too short to contain a MIC before any processing begins, and replaces the hardcoded size constant throughout the function. The vulnerable code path is reached whenever the driver processes an incoming TKIP-encrypted WiFi frame, so any unauthenticated attacker within wireless range of a device using the ipw2x00 driver can trigger the bug by transmitting a crafted short frame.

03

BranchIntroducedFixed inPatch commit
6.122.6.146.12.1129a7fb6736481
6.182.6.146.18.54ac7c08626f67
7.22.6.147.2.8bb7ae8910cc8
mainline2.6.147.3-rc406f42accaf3c