CVE-2024-3652: IKEv1 default AH/ESP responder can cause libreswan to abort and restart

Published Apr 11, 2024
·
Updated

IKEv1 default AH/ESP responder can cause libreswan to abort and restart

Other sources

libreswan can crash and restart when it is acting as an IKEv1 responder with AH/ESP default setting, when no esp= line is present in the connection configuration. The bug is triggered when after IKEv1 authentication has succeeded (via Main Mode or Aggressive Mode), a Quick Mode message is received containing a bogus AES-GMAC proposal.

When such a connection is automatically added on startup using the auto=keyword, it can cause repeated crashes leading to a Denial of Service. No Remote Code Execution is possible. IKEv2 connections are not vulnerable.

Vulnerable versions : libreswan 3.22 - 4.14

https://libreswan.org/security/CVE-2024-3652 https://github.com/libreswan/libreswan/issues/1665

Red Hat

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

NVD

Affected Software

6 affected componentsFixes available
redhat/libreswan<4.15
4.15
redhat/libreswan<5.0
5.0
libreswan Libreswan>=3.22<4.15
Microsoft azl3 libreswan 4.15-1<4.15-1
4.15-1
Microsoft cbl2 libreswan 4.14-2<4.14-2
4.14-2
Microsoft azl3 libreswan 4.7-7<4.15-1
4.15-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/libreswan to a version that resolves this vulnerability.

    Fixed in 4.15
  2. Upgrade

    Upgrade redhat/libreswan to a version that resolves this vulnerability.

    Fixed in 5.0
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.15-1
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.14-2
  5. Upgrade

    Upgrade libreswan to a version that resolves this vulnerability.

    Fixed in 4.15
  6. Configuration

    For IKEv1 connections where Libreswan acts as a responder, ensure the connection configuration includes an explicit esp= line; do not rely on the default AH/ESP responder behavior when esp= is not present, since this can trigger repeated crashes/DoS when a bogus AES-GMAC Quick Mode proposal is received.

    Libreswan connection configuration (IKEv1) esp= = must be explicitly specified (add an esp= line)

Event History

Apr 11, 2024
CVE Published
via MITRE·01:32 AM
Data Sourced
via MITRE·01:32 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Apr 22, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Updated
via Microsoft·07:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-3652?

CVE-2024-3652 has been classified as a high severity vulnerability due to its potential to cause crashes in the libreswan software.

2

How do I fix CVE-2024-3652?

To fix CVE-2024-3652, update libreswan to version 4.15 or 5.0.

3

What environments are affected by CVE-2024-3652?

CVE-2024-3652 affects libreswan when it is configured as an IKEv1 responder without an esp= line in the connection configuration.

4

What actions trigger CVE-2024-3652?

CVE-2024-3652 is triggered after successful IKEv1 authentication if a Quick Mode message is processed without the necessary configuration.

5

Is CVE-2024-3652 exploitable remotely?

Yes, CVE-2024-3652 can be exploited remotely if the attacker can interact with the libreswan service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203