REDHAT-BUG-2501764: Medium severity libreswan Libreswan vulnerability
Libreswan contains a reachable assertion in the X.509 certificate processing path when operating in FIPS mode. After calling CERTExtractPublicKey(), the returned public key is asserted to be non-NULL, although the function may legitimately return NULL if public key extraction fails (for example, when processing a certificate with an RSA exponent of zero). An unauthenticated remote attacker can send a specially crafted CERT payload during an IKEv1 or IKEv2 exchange to trigger the assertion and terminate the daemon, resulting in a denial of service. The issue is only reachable when Libreswan is running in FIPS mode and certificate-based authentication is in use with at least one CA certificate loaded in the Libreswan NSS database; deployments using only Pre-Shared Key (PSK) authentication without loaded CA certificates are not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2501764?
The severity of REDHAT-BUG-2501764 is classified as medium, rated at 4.
What vulnerabilities are associated with REDHAT-BUG-2501764?
REDHAT-BUG-2501764 is associated with an assertion failure in the X.509 certificate processing when Libreswan operates in FIPS mode.
How do I fix REDHAT-BUG-2501764?
To fix REDHAT-BUG-2501764, ensure that you update to the latest patched version of Libreswan as recommended in security advisories.
What impact does REDHAT-BUG-2501764 have on systems using Libreswan?
REDHAT-BUG-2501764 could potentially lead to system crashes or security exposure due to incorrect handling of public key extraction.
Is REDHAT-BUG-2501764 specific to certain configurations of Libreswan?
Yes, REDHAT-BUG-2501764 specifically affects Libreswan when it is configured to operate in FIPS mode.