The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libreswan | Jun 26, 2024 | Apr 11, 2024 |
| Alpine Linux | — | Upgrade libreswan | Aug 22, 2024 | Apr 11, 2024 |
| Amazon Linux Ami 2 | — | Upgrade libreswanUpgrade libreswan-debuginfo | Jul 23, 2024 | Apr 11, 2024 |
| Amazon_linux_2023 | — | Upgrade libreswan-debuginfoUpgrade libreswan-debugsourceUpgrade libreswan | Feb 17, 2025 | Apr 15, 2024 |
| Debian | — | Upgrade libreswanNo solution exists | May 15, 2025 | Apr 11, 2024 |
| Oracle_linux | — | Upgrade libreswan | Jun 24, 2024 | Apr 15, 2024 |
| Redhat Openshift | — | Upgrade libreswan | Jan 10, 2025 | Apr 11, 2024 |
| Redhat_linux | — | No solution existsUpgrade libreswan-debugsourceUpgrade libreswan-debuginfoUpgrade libreswan | Jun 26, 2024 | Apr 11, 2024 |
| Rocky_linux | — | Upgrade libreswanUpgrade libreswan-debuginfoUpgrade libreswan-debugsource | Jul 3, 2024 | Apr 11, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub