Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50722

Опубликовано: 24 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected.

A flaw was found in Libreswan's implementation of IKEv2 authentication when processing signatures utilizing the RSASSA-PKCS1-v1_5 scheme. The RSA_authenticate_hash_signature_pkcs1_1_5_rsa() function does not correctly validate the DER encoding of the ASN.1 digest. A remote, unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted IKEv2 AUTH payload with a shorter-than-expected hash value. This triggers an internal assertion failure, causing the Libreswan daemon to abort and restart, leading to a Denial of Service (DoS). Furthermore, if the Libreswan gateway accepts connections using weak public RSA exponents (such as e=3), an attacker could execute a Bleichenbacher-style signature forgery attack to achieve an authentication bypass.

Отчет

Red Hat Product Security rates this as having an Moderate security impact. This Moderate severity rating reflects the deployment reality on modern enterprise platforms. The worst-case authentication bypass vector is effectively non-exploitable due to system-wide Crypto-Policies that strictly block the weak RSA exponents required for the attack. Furthermore, the resulting Denial of Service is limited to a controlled process abort via an internal assertion check. Because the Libreswan service is natively managed by systemd with automatic fault-recovery rules enabled by default, the daemon will instantly restart following a crash. Consequently, a sustained outage requires a continuous and high-volume malicious packet flood, significantly lowering the real-world operational risk.

Меры по смягчению последствий

If upgrading to Libreswan is not immediately feasible, this vulnerability can be mitigated by enforcing modern signature algorithms, which effectively prevents Libreswan from falling back to the vulnerable legacy parser logic. Explicitly configure your authby (or leftauth/rightauth) parameters in /etc/ipsec.conf to exclusively permit ECDSA and RSASSA-PSS: authby=ecdsa,rsa-sha2 Note: Applying this mitigation will drop compatibility with native Windows VPN clients that do not support RSASSA-PSS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreswanOut of support scope
Red Hat Enterprise Linux 7libreswanAffected
Red Hat OpenShift Container Platform 4libreswanAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Fast Datapath for Red Hat Enterprise Linux 9libreswanFixedRHSA-2026:4698627.07.2026
Red Hat Enterprise Linux 10libreswanFixedRHSA-2026:4639827.07.2026
Red Hat Enterprise Linux 8libreswanFixedRHSA-2026:4639627.07.2026
Red Hat Enterprise Linux 9libreswanFixedRHSA-2026:4639727.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2494148librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
28 дней назад

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected.

CVSS3: 8.1
nvd
28 дней назад

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected.

CVSS3: 8.1
msrc
27 дней назад

IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload

CVSS3: 8.1
debian
28 дней назад

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_ ...

CVSS3: 8.1
github
28 дней назад

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected.

7.5 High

CVSS3