Executive brief
OpenBSD's TKIP wireless security implementation contains an inverted logic check that disables the intended attack countermeasure. Attackers within radio range can send specially crafted wireless frames to trigger denial-of-service attacks, deauthenticating all TKIP-connected devices for up to 90 seconds and blocking reconnection. Additionally, the bug allows actual key-recovery attacks to proceed undetected. While TKIP is disabled by default, organizations still using legacy WPA1/TKIP wireless networks are exposed.
Technical details
The vulnerability is a logic inversion (CWE-1025) in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c. The 60-second countermeasure window check uses >= (greater-than-or-equal) when it should use < (less-than), causing TKIP MIC failure countermeasures to activate when failures are outside the 60-second window and to be discarded when they occur within it—the opposite of the intended behavior per IEEE 802.11-2012. An unauthenticated attacker within RF range can trigger the vulnerability by sending two malformed TKIP-encrypted frames separated by more than 60 seconds, causing the access point to deauthenticate all associated TKIP clients and block reassociation for 60–90 seconds. The vulnerability is reachable from the decryption path (ieee80211_tkip_decrypt) and EAPOL input path (ieee80211_pae_input.c) with no authentication required. The fix, committed as 1ee99df, changes the comparison operator from >= to <.
Affected products
- OpenBSD OpenBSD OpenBSD-current prior to 2026-07-15 with WPA1/TKIP enabled
Timeline
- 2026-08-06: disclosed
- 2026-07-15: patched: Fixed in commit 1ee99dfcc4ddc87afc6395d5d3094e9d2314fb5a
- 2026-06-18: other: Vulnerability reported to OpenBSD