The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.
https://lists.libreswan.org/pipermail/swan-announce/2013/000007.html
https://github.com/libreswan/libreswan/commit/2899351224fe2940aec37d7656e1e392c0fe07f0
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-7071