DSA-5368-1 libreswan -- security update

Related Vulnerabilities: CVE-2023-23009  

It was discovered that the libreswan IPsec implementation could be forced into a crash/restart via malformed IKEv2 packets after peer authentication, resulting in denial of service. For the stable distribution (bullseye), this problem has been fixed in version 4.3-1+deb11u3. We recommend that you upgrade your libreswan packages. For the detailed security status of libreswan please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libreswan

Debian Security Advisory

DSA-5368-1 libreswan -- security update

Date Reported:
03 Mar 2023
Affected Packages:
libreswan
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 1031821.
In Mitre's CVE dictionary: CVE-2023-23009.
More information:

It was discovered that the libreswan IPsec implementation could be forced into a crash/restart via malformed IKEv2 packets after peer authentication, resulting in denial of service.

For the stable distribution (bullseye), this problem has been fixed in version 4.3-1+deb11u3.

We recommend that you upgrade your libreswan packages.

For the detailed security status of libreswan please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libreswan