๐Ÿ” CVE Alert

CVE-2026-56101

MEDIUM 5.3

OpenBSD ieee80211_crypto_tkip.c TKIP MIC Countermeasure Logic Inversion DoS

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger denial of service by sending two malformed TKIP frames separated by more than 60 seconds. Attackers can exploit the reversed TKIP MIC failure countermeasure window check to deauthenticate all associated TKIP stations and block reassociation for up to 90 seconds, while within-window MIC failures that should engage countermeasures are silently discarded, leaving key-recovery attempts undetected.

CWE CWE-697
Vendor openbsd
Product openbsd
Published Sep 8, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for openbsd openbsd

Be the first to know when new medium vulnerabilities affecting openbsd openbsd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

OpenBSD / OpenBSD
0 < 1ee99dfcc4ddc87afc6395d5d3094e9d2314fb5a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
pop.argus-systems.ai: https://pop.argus-systems.ai/advisory/adv-209.html github.com: https://github.com/openbsd/src/commit/1ee99dfcc4ddc87afc6395d5d3094e9d2314fb5a vulncheck.com: https://www.vulncheck.com/advisories/openbsd-ieee80211-crypto-tkip-c-tkip-mic-countermeasure-logic-inversion-dos

Credits

Argus Systems