NULL pointer dereference in libreswan - CVE-2022-23094

 

NULL pointer dereference in libreswan - CVE-2022-23094

Published: January 12, 2022


Vulnerability identifier: #VU59521
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23094
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when processing malformed IKEv1 packets. A remote attacker can send specially crafted IKEv1 packet to the application, trigger a NULL pointer dereference error during a logging action on the rejected IKEv1 packet and crash the pluto daemon.


Affected software

libreswan
libreswan (Debian package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libreswan (Red Hat package)
libreswan
libreswan-debugsource
libreswan-help
libreswan-debuginfo
Red Hat OpenShift Container Platform
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Fedora

How to mitigate CVE-2022-23094

Install updates from vendor's website.

libreswan - update to 4.6
libreswan (Debian package) - update to 4.3-1+deb11u1
Red Hat OpenShift Container Platform - update to 4.7.43
libreswan (Red Hat package) - addressed in versions 4.3-6.el8_4, 4.4-4.el8_5
libreswan - update to 4.4-4.0.1
libreswan - update to 4.5-2
libreswan-debugsource - update to 4.5-2
libreswan-help - update to 4.5-2
libreswan-debuginfo - update to 4.5-2
libreswan - addressed in versions 4.6-1.fc34, 4.6-1.fc35

External References

Related Security Bulletins