---
id: CVE-2026-98193
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: libipw: reject TKIP frames without a full MIC

  libipw_michael_mic_verify() assumes that an skb contains an eight-byte
  Michael MIC
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: libipw: reject TKIP frames without a full MIC

  libipw_michael_mic_verify() assumes that an skb contains an eight-byte
  Michael MIC. A short TKIP frame makes the un…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= b453872c35cfcbdbf5a794737817f7d4e7b1b579 <
    9a7fb67364817710c96785ff86b71a2711ee92cb
  - >-
    Linux >= b453872c35cfcbdbf5a794737817f7d4e7b1b579 <
    ac7c08626f67844336086cf563f417566b76f0d7
  - >-
    Linux >= b453872c35cfcbdbf5a794737817f7d4e7b1b579 <
    bb7ae8910cc886885aea95abb7c2e578a2341646
  - >-
    Linux >= b453872c35cfcbdbf5a794737817f7d4e7b1b579 <
    06f42accaf3c6aecab1dcc57f68dde6c06c8b380
  - Linux 2.6.14
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:04.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98193'
references:
  - url: 'https://git.kernel.org/stable/c/06f42accaf3c6aecab1dcc57f68dde6c06c8b380'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9a7fb67364817710c96785ff86b71a2711ee92cb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ac7c08626f67844336086cf563f417566b76f0d7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bb7ae8910cc886885aea95abb7c2e578a2341646'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.447Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: libipw: reject TKIP frames without a full MIC

libipw_michael_mic_verify() assumes that an skb contains an eight-byte
Michael MIC. A short TKIP frame makes the unsigned payload length wrap,
causing michael_mic() to read past the skb.

Check that the MIC is present before verifying it, and use the existing
MICHAEL_MIC_LEN constant for all MIC lengths in the verifier.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
