Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 9: MGASA-2024-0113 Critical Libreswan Denial Of Service

mageia
Calendar Grey April 6, 2024
Dist Mageia Esm H88
A recent security patch for Libreswan tackles significant vulnerabilities that could result in Denial of Service attacks and connectivity disruptions.
The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secre...

Summary

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service. (CVE-2024-2357)

References

- https://bugs.mageia.org/show_bug.cgi?id=32996

- https://libreswan.org/security/CVE-2024-2357/CVE-2024-2357.txt

- https://www.cve.org/CVERecord?id=CVE-2024-2357

Resolution

SRPMS

- 9/core/libreswan-4.14-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0113.html
Type: security
CVE: CVE-2024-2357

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here