Reachable assertion in libreswan - CVE-2024-3652
Published: April 15, 2024 / Updated: April 23, 2024
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion within the compute_proto_keymat() function when handling IKEv1 packets within the default AH/ESP responder. A remote authenticated user can send specially crafted packets to the server and perform a denial of service (DoS) attack.
Affected software
Amazon Linux AMI
Oracle Linux
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
openEuler
Fedora
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libreswan (Red Hat package)
libreswan-doc
libreswan
libreswan-help
libreswan-debuginfo
libreswan-debugsource
Juniper Junos Space
Red Hat OpenShift Container Platform
How to mitigate CVE-2024-3652
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Junos Space - update to 24.1R3
libreswan (Red Hat package) - addressed in versions 4.5-1.el8_6.3, 4.12-2.el9_4.1
libreswan-doc - update to 4.12-2
libreswan - addressed in versions 4.12-2, 4.12-2.0.2
libreswan - update to 4.12-3
Red Hat OpenShift Container Platform - addressed in versions 4.12.61, 4.13.45, 4.14.33, 4.14.41, 4.16.3, 4.16.15, 4.17.0
libreswan-help - update to 4.15-1
libreswan-debuginfo - update to 4.15-1
libreswan-debugsource - update to 4.15-1
libreswan - update to 4.15-1
libreswan - addressed in versions 4.15-1.fc39, 4.15-1.fc40, 4.15-2.fc41
External References
Related Security Bulletins
- Denial of service in libreswan
- openEuler update for libreswan
- Fedora 41 update for libreswan
- Fedora 40 update for libreswan
- Fedora 39 update for libreswan
- Red Hat Enterprise Linux 9 update for libreswan
- Red Hat Enterprise Linux 8 update for libreswan
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Amazon Linux AMI update for libreswan
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Anolis OS update for libreswan
- Anolis OS update for libreswan
- Junos Space update for third-party components