Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2026-12413

3 месяца назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-12413

3 месяца назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-12413

3 месяца назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-12413

3 месяца назад

IKEv2 Denial of Service via malformed fragmentation

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-12413

3 месяца назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemo ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vj68-68x2-jwjq

3 месяца назад

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:46398

около 2 месяцев назад

Important: libreswan security update

EPSS: Низкий
rocky логотип

RLSA-2026:46397

около 2 месяцев назад

Important: libreswan security update

EPSS: Низкий
rocky логотип

RLSA-2026:46396

около 2 месяцев назад

Important: libreswan security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-46398

около 2 месяцев назад

ELSA-2026-46398: libreswan security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-46397

около 2 месяцев назад

ELSA-2026-46397: libreswan security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-46396

около 2 месяцев назад

ELSA-2026-46396: libreswan security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-12413

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-12413

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-12413

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
1%
Низкий
3 месяца назад
msrc логотип
CVE-2026-12413

IKEv2 Denial of Service via malformed fragmentation

CVSS3: 7.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-12413

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemo ...

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-vj68-68x2-jwjq

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS3: 7.5
1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:46398

Important: libreswan security update

около 2 месяцев назад
rocky логотип
RLSA-2026:46397

Important: libreswan security update

около 2 месяцев назад
rocky логотип
RLSA-2026:46396

Important: libreswan security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-46398

ELSA-2026-46398: libreswan security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-46397

ELSA-2026-46397: libreswan security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-46396

ELSA-2026-46396: libreswan security update (IMPORTANT)

около 2 месяцев назад

Уязвимостей на страницу