REDHAT-BUG-2187165: High severity libreswan vulnerability
When an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender re-uses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible.
https://github.com/libreswan/libreswan/issues/1039
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2187165?
The severity of REDHAT-BUG-2187165 is classified as moderate.
What software is affected by REDHAT-BUG-2187165?
The vulnerability REDHAT-BUG-2187165 affects Libreswan versions that utilize IKEv1 Aggressive Mode.
How do I fix REDHAT-BUG-2187165?
To fix REDHAT-BUG-2187165, you need to update to the latest version of Libreswan that addresses this vulnerability.
What are the potential risks associated with REDHAT-BUG-2187165?
The potential risks of REDHAT-BUG-2187165 include possible denial of service or state machine confusion in the pluto daemon.
Is there a workaround for REDHAT-BUG-2187165?
Currently, there are no documented workarounds for REDHAT-BUG-2187165, so updating is the recommended course of action.