Reachable assertion in libreswan - CVE-2026-12413
Published: June 25, 2026
libreswan
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an assertion failure caused by improper bounds checking in reassemble_v2_incoming_fragments() when processing invalidly formatted IKEv2 fragments. A remote attacker can send specially crafted fragmented IKEv2 packets to cause a denial of service.
Only IKEv2 configurations with fragmentation enabled are vulnerable. IKEv1 is not affected.