NA

CVE-2024-3652

Published: 11/04/2024 Updated: 01/05/2024

Vulnerability Summary

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1069194 libreswan: CVE-2024-3652: IKEv1 default AH/ESP responder can crash and restart Package: src:libreswan; Maintainer for src:libreswan is Daniel Kahn Gillmor <dkg@fifthhorsemannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 17 Apr 2024 19:27:01 UTC Severity: impo ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> libreswan: IKEv1 default AH/ESP responder can crash and restart <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: D ...