Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2026-14957

20 дней назад

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-14957

2 месяца назад

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-14957

20 дней назад

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-14957

19 дней назад

FIPS mode assertion failure via malicious CERT payload

EPSS: Низкий
debian логотип

CVE-2026-14957

20 дней назад

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_Extra ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x2hf-3rgr-r89x

20 дней назад

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:46398

около 2 месяцев назад

Important: libreswan security update

EPSS: Низкий
rocky логотип

RLSA-2026:46397

около 2 месяцев назад

Important: libreswan security update

EPSS: Низкий
rocky логотип

RLSA-2026:46396

около 2 месяцев назад

Important: libreswan security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-46398

около 2 месяцев назад

ELSA-2026-46398: libreswan security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-46397

около 2 месяцев назад

ELSA-2026-46397: libreswan security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-46396

около 2 месяцев назад

ELSA-2026-46396: libreswan security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-14957

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.

CVSS3: 7.5
1%
Низкий
20 дней назад
redhat логотип
CVE-2026-14957

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-14957

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.

CVSS3: 7.5
1%
Низкий
20 дней назад
msrc логотип
CVE-2026-14957

FIPS mode assertion failure via malicious CERT payload

1%
Низкий
19 дней назад
debian логотип
CVE-2026-14957

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_Extra ...

CVSS3: 7.5
1%
Низкий
20 дней назад
github логотип
GHSA-x2hf-3rgr-r89x

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.

CVSS3: 7.5
1%
Низкий
20 дней назад
rocky логотип
RLSA-2026:46398

Important: libreswan security update

около 2 месяцев назад
rocky логотип
RLSA-2026:46397

Important: libreswan security update

около 2 месяцев назад
rocky логотип
RLSA-2026:46396

Important: libreswan security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-46398

ELSA-2026-46398: libreswan security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-46397

ELSA-2026-46397: libreswan security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-46396

ELSA-2026-46396: libreswan security update (IMPORTANT)

около 2 месяцев назад

Уязвимостей на страницу