The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8357 http://linux.oracle.com/errata/ELSA-2024-8357.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: NetworkManager-libreswan-1.2.4-2.0.1.el7.aarch64.rpm NetworkManager-libreswan-gnome-1.2.4-2.0.1.el7.aarch64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//NetworkManager-libreswan-1.2.4-2.0.1.el7.src.rpm Related CVEs: CVE-2024-9050 Description of changes: [1.2.4-2.0.1] - Fix improper escaping of Libreswan configuration [CVE-2024-9050][Orabug: 37206712] _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8357 http://linux.oracle.com/errata/ELSA-2024-8357.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: NetworkManager-libreswan-1.2.4-2.0.1.el7.x86_64.rpm NetworkManager-libreswan-gnome-1.2.4-2.0.1.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//NetworkManager-libreswan-1.2.4-2.0.1.el7.src.rpm Related CVEs: CVE-2024-9050 Description of changes: [1.2.4-2.0.1] - Fix improper escaping of Libreswan configuration [CVE-2024-9050][Orabug: 37206712] _______________________________________________ El-errata mailing list
This is an update to 1.2.24 release of NetworkManager-libreswan, the IPSec VPN plugin for NetworkManager. It fixes a local privilege escalation bug due to improper escaping of Libreswan configuration. (CVE-2024-9050). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-d20b38c63f 2024-10-31 01:38:05.886403 -------------------------------------------------------------------------------- Name : NetworkManager-libreswan Product : Fedora 39 Version : 1.2.24 Release : 1.fc39 URL : https://gitlab.gnome.org/GNOME/NetworkManager-libreswan Summary : NetworkManager VPN plug-in for IPsec VPN Description : This package contains software for integrating the libreswan VPN software with NetworkManager and the GNOME desktop -------------------------------------------------------------------------------- Update Information: This is an update to 1.2.24 release of NetworkManager-libreswan, the IPSec VPN plugin for NetworkManager. It fixes a local privilege escalation bug due to improper escaping of Libreswan configuration. (CVE-2024-9050) -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 22 2024 Lubomir Rintel - 1.2.24-1 - Update to 1.2.24 release - Fixes a local privilege escalation bug with severity "important" (CVE-2024-9050) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2320956 - CVE-2024-9050 NetworkManager-libreswan: Local privilege escalation via leftupdown [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2320956 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-d20b38c63f' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4376 http://linux.oracle.com/errata/ELSA-2024-4376.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libreswan-4.12-2.0.1.el8_10.4.x86_64.rpm aarch64: libreswan-4.12-2.0.1.el8_10.4.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//libreswan-4.12-2.0.1.el8_10.4.src.rpm Related CVEs: CVE-2024-3652 Description of changes: [4.12-2.0.1.4] - Add libreswan-oracle.patch to detect Oracle Linux distro [4.12-2.4] - Fix CVE-2024-3652 (RHEL-32482) _______________________________________________ El-errata mailing list
Moderate: libreswan security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:4050", "synopsis": "Moderate: libreswan security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for libreswan.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN).\n\nSecurity Fix(es):\n\n* libreswan: IKEv1 default AH/ESP responder can crash and restart (CVE-2024-3652)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2274448", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2274448", "description": ""}], "cves": [{"name": "CVE-2024-3652", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-3652", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-07-02T14:11:35.145045Z", "rpms": {"Rocky Linux 9": {"nvras": ["libreswan-0:4.12-2.el9_4.1.aarch64.rpm", "libreswan-0:4.12-2.el9_4.1.ppc64le.rpm", "libreswan-0:4.12-2.el9_4.1.s390x.rpm", "libreswan-0:4.12-2.el9_4.1.src.rpm", "libreswan-0:4.12-2.el9_4.1.x86_64.rpm", "libreswan-debuginfo-0:4.12-2.el9_4.1.aarch64.rpm", "libreswan-debuginfo-0:4.12-2.el9_4.1.ppc64le.rpm", "libreswan-debuginfo-0:4.12-2.el9_4.1.s390x.rpm", "libreswan-debuginfo-0:4.12-2.el9_4.1.x86_64.rpm", "libreswan-debugsource-0:4.12-2.el9_4.1.aarch64.rpm","libreswan-debugsource-0:4.12-2.el9_4.1.ppc64le.rpm", "libreswan-debugsource-0:4.12-2.el9_4.1.s390x.rpm", "libreswan-debugsource-0:4.12-2.el9_4.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A recent security patch for libreswan identifies potential risks that could lead to service interruptions in Rocky Linux 9, specifically regarding IPsec VPN connections.. Rocky Linux Security, Libreswan Update, IPsec Issue. . LinuxSecurity.com Team
Update to 4.15 for CVE-2024-3652. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-07c9cfd337 2024-07-01 01:33:14.869106 -------------------------------------------------------------------------------- Name : libreswan Product : Fedora 39 Version : 4.15 Release : 1.fc39 URL : https://libreswan.org/ Summary : Internet Key Exchange (IKEv1 and IKEv2) implementation for IPsec Description : Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks. Everything passing through the untrusted net is encrypted by the ipsec gateway machine and decrypted by the gateway at the other end of the tunnel. The resulting tunnel is a virtual private network or VPN. This package contains the daemons and userland tools for setting up Libreswan. Libreswan also supports IKEv2 (RFC7296) and Secure Labeling Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04 -------------------------------------------------------------------------------- Update Information: Update to 4.15 for CVE-2024-3652 -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 22 2024 Paul Wouters - 4.15-1 - Update libreswan to 4.15 for CVE-2024-3652 - Resolves rhbz#2274448 CVE-2024-3652 libreswan: IKEv1 default AH/ESP responder can crash and restart - Allow "ipsec import" to try importing PKCS#12 non-interactively if there is no password -------------------------------------------------------------------------------- References: [ 1 ] Bug #2274448 - CVE-2024-3652 libreswan: IKEv1 default AH/ESP responder can crash and restart https://bugzilla.redhat.com/show_bug.cgi?id=2274448 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-07c9cfd337' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4050 http://linux.oracle.com/errata/ELSA-2024-4050.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: libreswan-4.12-2.0.1.el9_4.1.x86_64.rpm aarch64: libreswan-4.12-2.0.1.el9_4.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//libreswan-4.12-2.0.1.el9_4.1.src.rpm Related CVEs: CVE-2024-3652 Description of changes: [4.12-2.0.1.1] - Add libreswan-oracle.patch to detect Oracle Linux distro [4.12-2.1] - Fix CVE-2024-3652 (RHEL-40102) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-2565 http://linux.oracle.com/errata/ELSA-2024-2565.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: libreswan-4.12-2.0.1.el9_4.x86_64.rpm aarch64: libreswan-4.12-2.0.1.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//libreswan-4.12-2.0.1.el9_4.src.rpm Related CVEs: CVE-2024-2357 Description of changes: [4.12-2.0.1] - Add libreswan-oracle.patch to detect Oracle Linux distro [4.12-2] - Fix CVE-2024-2357 (RHEL-32761) - x509: unpack IPv6 general names based on length (RHEL-32718) _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.