Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-46398

Опубликовано: 27 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-46398: libreswan security update (IMPORTANT)

[5.3.2-1.0.1]

  • Add libreswan-oracle.patch to detect Oracle Linux distro

[5.3.2-1]

  • Update to libreswan-5.3.2

[5.3.1-1]

  • Update to libreswan-5.3.1

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

libreswan

5.3.2-1.el10_2

libreswan-minimal

5.3.2-1.el10_2

Oracle Linux x86_64

libreswan

5.3.2-1.el10_2

libreswan-minimal

5.3.2-1.el10_2

Связанные уязвимости

rocky
4 дня назад

Important: libreswan security update

rocky
3 дня назад

Important: libreswan security update

CVSS3: 7.5
ubuntu
28 дней назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
redhat
около 1 месяца назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
nvd
28 дней назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.