Описание
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.
A flaw was found in Libreswan. An unauthenticated remote attacker can send a specially crafted X.509 certificate payload during an IKEv1 or IKEv2 exchange. This flaw occurs when Libreswan is operating in FIPS (Federal Information Processing Standards) mode and processing a certificate with an invalid public key, such as an RSA exponent of zero. This can trigger an assertion failure, leading to the termination of the daemon process and a denial of service.
Отчет
Moderate: This flaw in Libreswan, when operating in FIPS mode with certificate-based authentication, allows an unauthenticated remote attacker to trigger a denial of service. The assertion failure occurs during X.509 certificate processing with a malformed certificate, leading to the daemon crashing. This impact is limited to specific configurations where both FIPS mode and certificate-based authentication are actively utilized. It means, when Libreswan is running in FIPS mode and certificate-based authentication is in use with at least one CA certificate loaded in the Libreswan NSS database. Deployments using only Pre-Shared Key (PSK) authentication without loaded CA certificates are not affected.
Меры по смягчению последствий
No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security updates once they become available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libreswan | Out of support scope | ||
| Red Hat Enterprise Linux 7 | libreswan | Affected | ||
| Red Hat OpenShift Container Platform 4 | libreswan | Affected | ||
| Fast Datapath for Red Hat Enterprise Linux 9 | libreswan | Fixed | RHSA-2026:46986 | 27.07.2026 |
| Red Hat Enterprise Linux 10 | libreswan | Fixed | RHSA-2026:46398 | 27.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | libreswan | Fixed | RHSA-2026:55449 | 17.08.2026 |
| Red Hat Enterprise Linux 8 | libreswan | Fixed | RHSA-2026:46396 | 27.07.2026 |
| Red Hat Enterprise Linux 9 | libreswan | Fixed | RHSA-2026:46397 | 27.07.2026 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | libreswan | Fixed | RHSA-2026:61779 | 31.08.2026 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | libreswan | Fixed | RHSA-2026:61258 | 31.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_Extra ...
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.
EPSS
7.5 High
CVSS3