HIGH Introduced in 2.6.14
libipw MichaelMic OOB
CVE-2026-98193
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: wifi: libipw: reject TKIP frames without a full MIC libipw_michael_mic_verify() assumes that an skb contains an eight-byte Michael MIC. A short TKIP frame makes the unsigned payload length wrap, causing michael_mic() to read past the skb. Check that the MIC is present before verifying it, and use the existing MICHAEL_MIC_LEN constant for all MIC lengths in the verifier.
02KernelScan AI Analysis
Risk summary
An attacker within WiFi range of a device using the Intel ipw2x00 wireless driver with TKIP encryption can send a deliberately short TKIP frame to trigger an out-of-bounds read in the kernel. This can leak kernel memory contents or crash the system. No authentication or privileges are required—only wireless proximity to the target.
Vulnerability analysis
The TKIP Michael MIC verification routine in the Intel ipw2x00 WiFi driver assumes every received TKIP frame contains an eight-byte MIC trailer. When a frame shorter than the header plus eight bytes arrives, the unsigned payload-length calculation underflows to a very large value, causing the MIC computation function to read far past the end of the packet buffer—leaking kernel memory or triggering a page fault panic. The fix adds a length check that rejects frames too short to contain a MIC before any processing begins, and replaces the hardcoded size constant throughout the function. The vulnerable code path is reached whenever the driver processes an incoming TKIP-encrypted WiFi frame, so any unauthenticated attacker within wireless range of a device using the ipw2x00 driver can trigger the bug by transmitting a crafted short frame.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 2.6.14 | 6.12.112 | 9a7fb6736481 |
| 6.18 | 2.6.14 | 6.18.54 | ac7c08626f67 |
| 7.2 | 2.6.14 | 7.2.8 | bb7ae8910cc8 |
| mainline | 2.6.14 | 7.3-rc4 | 06f42accaf3c |