First published: Fri Aug 25 2023(Updated: )
An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libreswan Libreswan | >=3.0<4.0 | |
Libreswan Libreswan | >=4.0<4.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38712 is a vulnerability discovered in Libreswan 3.x and 4.x before 4.12 that can lead to a NULL pointer dereference.
The severity of CVE-2023-38712 is high, with a CVSS score of 7.5.
The vulnerability affects Libreswan versions 3.x to 4.0 and 4.0 to 4.11.
To fix CVE-2023-38712, update Libreswan to version 4.12 or later.
You can find more information about CVE-2023-38712 on the Libreswan GitHub page and the official Libreswan security advisory.