Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 40: FEDORA-2024-83ed0a6b02 Critical NetworkManager VPN Security Fix

fedora
Calendar Grey March 23, 2024
Dist Fedora Esm H88
The latest Libreswan roll-out for Fedora 40 tackles CVE-2024-2357, improving overall security through the implementation of padding corrections and support for Subject Alternative Names (SAN).
Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD

Summary

Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is

the Internet Protocol Security and uses strong cryptography to provide

both authentication and encryption services. These services allow you

to build secure tunnels through untrusted networks. Everything passing

through the untrusted net is encrypted by the ipsec gateway machine and

decrypted by the gateway at the other end of the tunnel. The resulting

tunnel is a virtual private network or VPN.

This package contains the daemons and userland tools for setting up

Libreswan.

Libreswan also supports IKEv2 (RFC7296) and Secure Labeling

Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04

Update Information:

Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD

Change Log

* Tue Mar 12 2024 Paul Wouters - 4.14-1 - Update to 4.14 for CVE-2024-2357

References

Fedora Update Notification FEDORA-2024-92f0c71a01 2024-03-23 00:20:56.400855 Name : libreswan Product : Fedora 40 Version : 4.14 Release : 1.fc40 URL : https://libreswan.org/ Summary : Internet Key Exchange (IKEv1 and IKEv2) implementation for IPsec Description : Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks. Everything passing through the untrusted net is encrypted by the ipsec gateway machine and decrypted by the gateway at the other end of the tunnel. The resulting tunnel is a virtual private network or VPN. This package contains the daemons and userland tools for setting up Libreswan. Libreswan also supports IKEv2 (RFC7296) and Secure Labeling Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-92f0c71a01' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libreswan
Product: Fedora 40
Version: 4.14
Release: 1.fc40
Summary: Internet Key Exchange (IKEv1 and IKEv2) implementation for IPsec

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here