Error Handling in libreswan - CVE-2024-2357
Published: March 12, 2024
Vulnerability identifier: #VU87342
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2357
CWE-ID: CWE-388
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect handling of a missing PreSharedKey when a connection is configured to use reSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup sing the auto= keyword, it can cause repeated crashes leading to a denial of service.Affected software
libreswan
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
openEuler
Fedora
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libreswan (Red Hat package)
libreswan
libreswan-doc
libreswan-debuginfo
libreswan-debugsource
libreswan-help
Red Hat OpenShift Container Platform
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
openEuler
Fedora
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libreswan (Red Hat package)
libreswan
libreswan-doc
libreswan-debuginfo
libreswan-debugsource
libreswan-help
Red Hat OpenShift Container Platform
How to mitigate CVE-2024-2357
Install updates from vendor's website.
libreswan - update to 4.13
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
libreswan (Red Hat package) - addressed in versions 4.5-1.el8_6.2, 4.6-3.el9_0.3, 4.9-3.el8_8.1, 4.9-5.el9_2.1, 4.12-1.el9_3.1, 4.12-2.el8_9.2, 4.12-2.el9_4
libreswan - addressed in versions 4.12-2.0.2, 4.14-1
libreswan - update to 4.12-3
libreswan-doc - update to 4.14-1
libreswan-debuginfo - update to 4.14-1
libreswan-debugsource - update to 4.14-1
libreswan-help - update to 4.14-1
libreswan - update to 4.14-1
libreswan - addressed in versions 4.14-1.fc38, 4.14-1.fc39, 4.14-1.fc40
Red Hat OpenShift Container Platform - update to 4.15.12
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
libreswan (Red Hat package) - addressed in versions 4.5-1.el8_6.2, 4.6-3.el9_0.3, 4.9-3.el8_8.1, 4.9-5.el9_2.1, 4.12-1.el9_3.1, 4.12-2.el8_9.2, 4.12-2.el9_4
libreswan - addressed in versions 4.12-2.0.2, 4.14-1
libreswan - update to 4.12-3
libreswan-doc - update to 4.14-1
libreswan-debuginfo - update to 4.14-1
libreswan-debugsource - update to 4.14-1
libreswan-help - update to 4.14-1
libreswan - update to 4.14-1
libreswan - addressed in versions 4.14-1.fc38, 4.14-1.fc39, 4.14-1.fc40
Red Hat OpenShift Container Platform - update to 4.15.12
External References
Related Security Bulletins
- Local denial of service in libreswan
- Fedora 40 update for libreswan
- Fedora 39 update for libreswan
- Fedora 38 update for libreswan
- openEuler update for libreswan
- openEuler 22.03 LTS SP1 update for libreswan
- Red Hat Enterprise Linux 8 update for libreswan
- Red Hat Enterprise Linux 9 update for libreswan
- Red Hat Enterprise Linux 8.8 Extended Update Support update for libreswan
- Red Hat Enterprise Linux 9.2 Extended Update Support update for libreswan
- Red Hat Enterprise Linux 8.6 update for libreswan
- Red Hat Enterprise Linux 9 update for libreswan
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Amazon Linux AMI update for libreswan
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Red Hat Enterprise Linux 9 update for libreswan
- Anolis OS update for libreswan
- Anolis OS update for libreswan