CVE-2026-56101
Awaiting Analysis Awaiting Analysis - Queue

Inverted TKIP MIC Check in OpenBSD Wireless Stack

Vulnerability report for CVE-2026-56101, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger denial of service by sending two malformed TKIP frames separated by more than 60 seconds. Attackers can exploit the reversed TKIP MIC failure countermeasure window check to deauthenticate all associated TKIP stations and block reassociation for up to 90 seconds, while within-window MIC failures that should engage countermeasures are silently discarded, leaving key-recovery attempts undetected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openbsd openbsd to 1ee99df (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-697 The product compares two entities in a security-relevant context, but the comparison is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in OpenBSD involves an inverted comparison in the ieee80211_michael_mic_failure() function. Unauthenticated attackers within RF range can send two malformed TKIP frames spaced more than 60 seconds apart to trigger a denial of service. The flaw allows attackers to deauthenticate all TKIP stations and block reassociation for up to 90 seconds by exploiting a reversed countermeasure window check.

Impact Analysis

This vulnerability can disrupt wireless network availability by causing temporary disconnections for all TKIP-enabled devices. Users may experience intermittent loss of connectivity for up to 90 seconds, potentially affecting real-time applications or critical communications.

Mitigation Strategies

Update OpenBSD to a version that includes commit 1ee99df or later to fix the inverted comparison in the TKIP MIC failure handling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56101. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart