CVE-2022-23094

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

Summary:

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

Reference Links(if available):

  • https://github.com/libreswan/libreswan/issues/585
  • https://libreswan.org/security/CVE-2022-23094
  • https://www.debian.org/security/2022/dsa-5048
  • https://lists.fedoraproject.org/archives/list/[email protected]/message/UFZ7WP5LNNBW5ADIOPDSPQ23SXZJRNMP/
  • https://lists.fedoraproject.org/archives/list/[email protected]/message/HPMIHAXWQUJAPCIGNJ5J5Q6ASWQBU7T5/
  • CVSS Score (if available)

    v2: / MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P

    v3: / HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    Links to Exploits(if available)