Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-12413

Опубликовано: 02 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*
Версия от 4.6 (включая) до 5.3.1 (исключая)

EPSS

Процентиль: 45%
0.00598
Низкий

7.5 High

CVSS3

Дефекты

CWE-193

Связанные уязвимости

CVSS3: 7.5
ubuntu
28 дней назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
msrc
27 дней назад

IKEv2 Denial of Service via malformed fragmentation

CVSS3: 7.5
debian
28 дней назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemo ...

CVSS3: 7.5
github
28 дней назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

EPSS

Процентиль: 45%
0.00598
Низкий

7.5 High

CVSS3

Дефекты

CWE-193