The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libreswan | Apr 30, 2024 | Mar 11, 2024 |
| Alpine Linux | — | Upgrade libreswan | Aug 22, 2024 | Mar 11, 2024 |
| Amazon_linux_2023 | — | Upgrade libreswanUpgrade libreswan-debuginfoUpgrade libreswan-debugsource | Feb 17, 2025 | Mar 11, 2024 |
| Debian | — | Upgrade libreswan | May 15, 2025 | Mar 11, 2024 |
| Oracle_linux | — | Upgrade libreswan | Apr 24, 2024 | Mar 11, 2024 |
| Redhat Openshift | — | Upgrade libreswan | Jan 10, 2025 | Mar 11, 2024 |
| Redhat_linux | — | No solution existsUpgrade libreswan-debugsourceUpgrade libreswan-debuginfoUpgrade libreswan | Apr 29, 2024 | Mar 11, 2024 |
| Rocky_linux | — | Upgrade libreswan-debuginfoUpgrade libreswanUpgrade libreswan-debugsource | May 8, 2024 | Mar 11, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub