« Volver al listado

CVE-2026-98193

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: libipw: reject TKIP frames without a full MIC

libipw_michael_mic_verify() assumes that an skb contains an eight-byte Michael MIC. A short TKIP frame makes the unsigned payload length wrap, causing michael_mic() to read past the skb.

Check that the MIC is present before verifying it, and use the existing MICHAEL_MIC_LEN constant for all MIC lengths in the verifier.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98193",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b453872c35cfcbdbf5a794737817f7d4e7b1b579",
              "lessThan": "9a7fb67364817710c96785ff86b71a2711ee92cb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b453872c35cfcbdbf5a794737817f7d4e7b1b579",
              "lessThan": "ac7c08626f67844336086cf563f417566b76f0d7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b453872c35cfcbdbf5a794737817f7d4e7b1b579",
              "lessThan": "bb7ae8910cc886885aea95abb7c2e578a2341646",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b453872c35cfcbdbf5a794737817f7d4e7b1b579",
              "lessThan": "06f42accaf3c6aecab1dcc57f68dde6c06c8b380",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:04.670",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/06f42accaf3c6aecab1dcc57f68dde6c06c8b380",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a7fb67364817710c96785ff86b71a2711ee92cb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ac7c08626f67844336086cf563f417566b76f0d7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bb7ae8910cc886885aea95abb7c2e578a2341646",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject TKIP frames without a full MIC\n\nlibipw_michael_mic_verify() assumes that an skb contains an eight-byte\nMichael MIC. A short TKIP frame makes the unsigned payload length wrap,\ncausing michael_mic() to read past the skb.\n\nCheck that the MIC is present before verifying it, and use the existing\nMICHAEL_MIC_LEN constant for all MIC lengths in the verifier."
    }
  ],
  "lastModified": "2026-10-06T09:18:04.670",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}