NA

CVE-2024-2357

Published: 11/03/2024 Updated: 23/03/2024

Vulnerability Summary

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1066059 libreswan: CVE-2024-2357 Package: src:libreswan; Maintainer for src:libreswan is Daniel Kahn Gillmor <dkg@fifthhorsemannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Mar 2024 21:24:01 UTC Severity: important Tags: security, upstream Found in versions libr ...