CVE-2022-23094: Null Pointer Dereference
Published Jan 15, 2022
·Updated
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
Affected Software
5 affected componentsFixes available
debian/libreswan
3.27-6+deb10u14.3-1+deb11u44.3-1+deb11u34.10-2+deb12u14.12-1
libreswan Libreswan>=4.2<4.6
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=10.0
Event History
Jan 15, 2022
CVE Published
via MITRE·01:37 AM
Data Sourced
via MITRE·01:37 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-23094.
2
What is the severity of CVE-2022-23094?
The severity of CVE-2022-23094 is high with a severity value of 7.5.
3
How does CVE-2022-23094 affect Libreswan?
CVE-2022-23094 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) in Libreswan versions 4.2 through 4.5.
4
How can I fix CVE-2022-23094?
You can fix CVE-2022-23094 by updating to Libreswan version 4.6 or applying the patch provided by the vendor.
5
Where can I find more information about CVE-2022-23094?
You can find more information about CVE-2022-23094 at the following references: [link1], [link2], [link3].