MGASA-2024-0113 - Updated libreswan packages fix security vulnerabilities

Publication date: 06 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0113.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-2357

The Libreswan Project was notified of an issue causing libreswan to
restart under some IKEv2 retransmit scenarios when a connection is
configured to use PreSharedKeys (authby=secret) and the connection
cannot find a matching configured secret. When such a connection is
automatically added on startup using the auto= keyword, it can cause
repeated crashes leading to a Denial of Service. (CVE-2024-2357)

References:
- https://bugs.mageia.org/show_bug.cgi?id=32996
- https://libreswan.org/security/CVE-2024-2357/CVE-2024-2357.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2357

SRPMS:
- 9/core/libreswan-4.14-1.mga9

Mageia 2024-0113: libreswan security update

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secre...

Summary

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service. (CVE-2024-2357)

References

- https://bugs.mageia.org/show_bug.cgi?id=32996

- https://libreswan.org/security/CVE-2024-2357/CVE-2024-2357.txt

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2357

Resolution

MGASA-2024-0113 - Updated libreswan packages fix security vulnerabilities

SRPMS

- 9/core/libreswan-4.14-1.mga9

Severity
Publication date: 06 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0113.html
Type: security
CVE: CVE-2024-2357

Related News