Reachable Assertion in libreswan - CVE-2023-23009
Published: March 1, 2023 / Updated: March 1, 2023
Vulnerability identifier: #VU72679
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23009
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion. A remote attacker can pass a specially crafted IKEv2 TS payload with an incorrect selector length and perform a denial of service (DoS) attack.
Affected software
libreswan
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libreswan (Debian package)
libreswan
libreswan-help
libreswan-debuginfo
libreswan-debugsource
libreswan (Red Hat package)
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libreswan (Debian package)
libreswan
libreswan-help
libreswan-debuginfo
libreswan-debugsource
libreswan (Red Hat package)
How to mitigate CVE-2023-23009
Install updates from vendor's website.
libreswan - update to 4.10
libreswan (Debian package) - update to 4.3-1+deb11u3
libreswan - update to 4.5-3
libreswan-help - update to 4.5-3
libreswan-debuginfo - update to 4.5-3
libreswan-debugsource - update to 4.5-3
libreswan (Red Hat package) - addressed in versions 4.6-3.el9_0.3, 4.9-2.el8_8.2, 4.9-2.el9_2
libreswan - addressed in versions 4.10-1.fc37, 4.10-1.fc38
libreswan (Debian package) - update to 4.3-1+deb11u3
libreswan - update to 4.5-3
libreswan-help - update to 4.5-3
libreswan-debuginfo - update to 4.5-3
libreswan-debugsource - update to 4.5-3
libreswan (Red Hat package) - addressed in versions 4.6-3.el9_0.3, 4.9-2.el8_8.2, 4.9-2.el9_2
libreswan - addressed in versions 4.10-1.fc37, 4.10-1.fc38
External References
Related Security Bulletins
- Denial of service in libreswan
- Debian update for libreswan
- Red Hat Enterprise Linux 9 update for libreswan
- Red Hat Enterprise Linux 8 update for libreswan
- Fedora 38 update for libreswan
- Fedora 37 update for libreswan
- openEuler 22.03 LTS update for libreswan
- openEuler 22.03 LTS SP1 update for libreswan
- Red Hat Enterprise Linux 9 update for libreswan