Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: DSA-5048-1 Critical: Libreswan Denial Of Service Risk

debian
Calendar Grey January 15, 2022
Debian Logo
Essential security patch for libreswan in Debian resolves denial of service vulnerability caused by improper IKEv1 packets.
It was discovered that the libreswan IPsec implementation could be forced into a crash/restart via a malformed IKEv1 packet, resulting in denial of service

Summary

For the stable distribution (bullseye), this problem has been fixed in
version 4.3-1+deb11u1.

We recommend that you upgrade your libreswan packages.

For the detailed security status of libreswan please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libreswan

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libreswan
CVE ID: CVE-2022-23094

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here