NA

CVE-2024-3652

Published: 11/04/2024 Updated: 01/05/2024

Vulnerability Summary

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1069194 libreswan: CVE-2024-3652: IKEv1 default AH/ESP responder can crash and restart Package: src:libreswan; Maintainer for src:libreswan is Daniel Kahn Gillmor <dkg@fifthhorsemannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 17 Apr 2024 19:27:01 UTC Severity: impo ...

Mailing Lists

Hello, I noticed I missed a few CVEs on libreswan recently as the project is not posting them here, I subscribed to their announce mailing-list to monitor that for work, and thought I could try to follow and post them here when there are new things That being said, here is the latest one: Vulnerability information ========================= The f ...