CVE-2026-98193: wifi: libipw: reject TKIP frames without a full MIC
In the Linux kernel, the following vulnerability has been resolved:
wifi: libipw: reject TKIP frames without a full MIC
libipwmichaelmicverify() assumes that an skb contains an eight-byte Michael MIC. A short TKIP frame makes the unsigned payload length wrap, causing michaelmic() to read past the skb.
Check that the MIC is present before verifying it, and use the existing MICHAELMICLEN constant for all MIC lengths in the verifier.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In libipw TKIP frame handling, reject frames without a full MIC before verification and use the existing MICHAEL_MIC_LEN constant for all MIC lengths in the verifier.