Description
There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:
- Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the
DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC
8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when
small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by
encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-
of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service.
Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not
affected. (CVE-2026-50722)
- An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued
exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore
unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-
one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to
abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not
set fragmentation=no are vulnerable. IKEv1 is not affected. (CVE-2026-12413)
- In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the
result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for
example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a
CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued
exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are
affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode
and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no
credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with
no CA certificates loaded in the NSS database are not vulnerable. (CVE-2026-14957)
- Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length
of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA
Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge
the SIG payload when small public exponents are being used (e.g., e=3), which could lead to impersonation.
Additionally, a remote attacker, by encoding a shorter than expected hash in the SIG payload, could
trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation
causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications
of remote IKE peers are not affected. (CVE-2026-50721)
Solution
Update the libreswan library and its related packages to version 5.3.3-r0 or later.
Plugin Details
Supported Sensors: Agentless Assessment
Risk Information
Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 7/2/2026