CVE-2023-38711: Null Pointer Dereference
An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with IDIPV4ADDR or IDIPV6ADDR receives an IDcr payload with IDFQDN a NULL pointer dereference causes a crash and restart of the pluto daemon. NOTE: the earliest affected version is 4.6.
Other sources
An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with IDIPV4ADDR or IDIPV6ADDR receives an IDcr payload with IDFQDN, a NULL pointer dereference causes a crash and restart of the pluto daemon. NOTE: the earliest affected version is 4.6.
— MITRE
When an IKEv1 Quick Mode connection configured with IDIPV4ADDR or IDIPV6ADDR, receives an IDcr payload with IDFQDN, a null pointer dereference causes a crash and restart of the pluto daemon.
https://libreswan.org/security/CVE-2023-38711/CVE-2023-38711.txt
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38711?
CVE-2023-38711 is a vulnerability in Libreswan versions before 4.12 that can cause a crash and restart of the pluto daemon when an IKEv1 Quick Mode connection receives an IDcr payload with ID_FQDN.
How severe is the CVE-2023-38711 vulnerability?
The severity of CVE-2023-38711 is high, with a CVSS severity score of 7.5.
Which versions of Libreswan are affected by CVE-2023-38711?
Libreswan versions from 4.6 to 4.12 are affected by CVE-2023-38711.
How can I fix the CVE-2023-38711 vulnerability?
To fix CVE-2023-38711, update Libreswan to version 4.12 or later.
Where can I find more information about CVE-2023-38711?
You can find more information about CVE-2023-38711 on the Libreswan GitHub page and the Libreswan security advisory page.