NULL pointer dereference in libreswan - CVE-2026-14957

 

NULL pointer dereference in libreswan - CVE-2026-14957

Published: July 18, 2026


Vulnerability identifier: #VU138388
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-14957
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of a null return value in certificate public key extraction in programs/pluto/nss_cert_verify.c when processing a malformed X.509 CERT payload in FIPS mode. A remote attacker can send a specially crafted certificate payload to cause a denial of service.

Exploitation is only possible when the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. CERT payloads can be processed before peer authentication, and both IKEv1 and IKEv2 are affected.


Affected software

libreswan
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Fast Datapath
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libreswan (Red Hat package)
libreswan
libreswan-debuginfo
libreswan-debugsource
libreswan-help

How to mitigate CVE-2026-14957

Install security update from vendor's website.

libreswan - update to 5.3.2
libreswan (Red Hat package) - addressed in versions 4.9-5.el9_2.5, 4.12-2.el8_10.6, 4.12-3.el9_4.2, 4.15-8.el9_6.1, 4.15-10.el9_8, 5.3.2-1.el9fdp, 5.3.2-1.el10_2
libreswan - update to 4.12-2.0.2
libreswan - update to 4.15-4
libreswan-debuginfo - update to 4.15-4
libreswan-debugsource - update to 4.15-4
libreswan-help - update to 4.15-4
libreswan - addressed in versions 5.3.2-2.fc43, 5.3.2-2.fc44

External References

Related Security Bulletins