Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-38710

Опубликовано: 08 авг. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol ID number of 0 or 1, an error notify INVALID_SPI is sent back. The notify payload's protocol ID is copied from the incoming packet, but the code that verifies outgoing packets fails an assertion that the protocol ID must be ESP (2) or AH(3) and causes the pluto daemon to crash and restart. NOTE: the earliest affected version is 3.20.

An assertion failure flaw was found in the Libreswan package that occurs when processing IKEv2 REKEY requests. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol ID number of 0 or 1, an error notification INVALID_SPI is sent back. The notify payload's protocol ID is copied from the incoming packet, but the code that verifies outgoing packets fails an assertion that the protocol ID must be ESP (2) or AH(3). This flaw allows a malicious client or attacker to send a malformed IKEv2 REKEY packet, causing a crash and restarting the libreswan pluto daemon. When sent continuously, this could lead to a denial of service attack.

Отчет

IKEv2 REKEY requests are only processed when received from authenticated peers, limiting the scope of possible attackers to peers who have successfully authenticated.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreswanNot affected
Red Hat Enterprise Linux 7libreswanOut of support scope
Red Hat Enterprise Linux 8libreswanFixedRHSA-2023:705214.11.2023
Red Hat Enterprise Linux 9libreswanFixedRHSA-2023:654907.11.2023
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionslibreswanFixedRHSA-2024:1059402.12.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportlibreswanFixedRHSA-2025:030914.01.2025
Red Hat OpenShift Container Platform 4.15libreswanFixedRHBA-2024:1156502.01.2025
Red Hat OpenShift Container Platform 4.16libreswanFixedRHBA-2024:1150502.01.2025
Red Hat OpenShift Container Platform 4.17libreswanFixedRHBA-2024:1152502.01.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2225368libreswan: Invalid IKEv2 REKEY proposal causes restart

EPSS

Процентиль: 20%
0.00062
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol ID number of 0 or 1, an error notify INVALID_SPI is sent back. The notify payload's protocol ID is copied from the incoming packet, but the code that verifies outgoing packets fails an assertion that the protocol ID must be ESP (2) or AH(3) and causes the pluto daemon to crash and restart. NOTE: the earliest affected version is 3.20.

CVSS3: 6.5
nvd
почти 2 года назад

An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol ID number of 0 or 1, an error notify INVALID_SPI is sent back. The notify payload's protocol ID is copied from the incoming packet, but the code that verifies outgoing packets fails an assertion that the protocol ID must be ESP (2) or AH(3) and causes the pluto daemon to crash and restart. NOTE: the earliest affected version is 3.20.

CVSS3: 6.5
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 6.5
debian
почти 2 года назад

An issue was discovered in Libreswan before 4.12. When an IKEv2 Child ...

CVSS3: 7.5
github
почти 2 года назад

An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol ID number of 0 or 1, an error notify INVALID_SPI is sent back. The notify payload's protocol ID is copied from the incoming packet, but the code that verifies outgoing packets fails an assertion that the protocol ID must be ESP (2) or AH(3) and causes the pluto daemon to crash and restart. NOTE: the earliest affected version is 3.20.

EPSS

Процентиль: 20%
0.00062
Низкий

6.5 Medium

CVSS3