CVE-2023-2295: High severity libreswan vulnerability
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Other sources
The libreswan flaw CVE-2023-30570 (bug 2187165) was addressed in Red Hat Enterprise Linux 8 via erratum RHSA-2023:2122 and in Red Hat Enterprise Linux 9 via erratum RHSA-2023:2120, released on May 04, 2023:
https://access.redhat.com/errata/RHSA-2023:2122 https://access.redhat.com/errata/RHSA-2023:2120
However, the fix for this issue was not included in the libreswan updates released as part of Red Hat Enterprise Linux 8.8 GA erratum (RHBA-2023:2865) and Red Hat Enterprise Linux 9.2 GA erratum (RHBA-2023:2355), causing a security regression of previously released fix. A new CVE-ID CVE-2023-2295 was assigned for this security regression.
Note that this issue and CVE-ID is specific to the libreswan packages as shipped with Red Hat Enterprise Linux and is not applicable to any upstream libreswan version or libreswan packages of any other vendor that are not directly based on Red Hat Enterprise Linux packages.
For more information about the original flaw, refer to the CVE page or bug linked above.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2295?
CVE-2023-2295 is a vulnerability found in the libreswan library that occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms.
What is the severity of CVE-2023-2295?
The severity of CVE-2023-2295 is high, with a severity value of 7.5.
How does CVE-2023-2295 affect the Libreswan library?
CVE-2023-2295 affects the Libreswan library by allowing an attacker to send an IKEv1 Aggressive Mode packet with unacceptable crypto algorithms and receive a response packet without a zero responder SPI.
Which software versions are affected by CVE-2023-2295?
CVE-2023-2295 affects Libreswan versions 4.9-1.el8 and 4.9-1.el9, as well as Redhat Enterprise Linux versions 8.0, 9.0, 8.8, 9.2, and Redhat Enterprise Linux Server versions 8.8, 9.2, and 8.8.
How can I fix CVE-2023-2295?
To fix CVE-2023-2295, it is recommended to update to a patched version of the libreswan library or apply the necessary security patches provided by Redhat.