CVE-2022-23094
published 2022-01-15CVE-2022-23094: Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.70%
84.4th percentile
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libreswan | < libreswan 4.6-1 (bookworm) | libreswan 4.6-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libreswan | libreswan | >= 0 < 4.3-1+deb11u1 | 4.3-1+deb11u1 |
| libreswan | libreswan | >= 0 < 4.6-1 | 4.6-1 |
| libreswan | libreswan | >= 0 < 4.6-1 | 4.6-1 |
| libreswan | libreswan | >= 0 < 4.6-1 | 4.6-1 |
| libreswan | libreswan | >= 4.2 < 4.6 | 4.6 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libreswan: Malicious IKEv1 packet can cause libreswan to restart
vendor_redhat·2022-01-11·CVSS 7.5
CVE-2022-23094 [HIGH] CWE-476 libreswan: Malicious IKEv1 packet can cause libreswan to restart
libreswan: Malicious IKEv1 packet can cause libreswan to restart
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
A vulnerability was found in libreswan. A malformed packet that is being rejected triggers a logging action that causes a NULL pointer dereference issue, leading to a crash of the pluto daemon.
Mitigation: If all configured connections are using IKEv2, the IKEv1 subsystem can be disabled by adding the option ikev1-policy=drop to the "config setup" section of ipsec.conf. Alternatively, libreswan can be compiled with USE_IKEv1=false.
If all remote peers are on static IP addresses, a firewall
Debian
CVE-2022-23094: libreswan - Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (...
vendor_debian·2022·CVSS 7.5
CVE-2022-23094 [HIGH] CVE-2022-23094: libreswan - Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (...
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
Scope: local
bookworm: resolved (fixed in 4.6-1)
bullseye: resolved (fixed in 4.3-1+deb11u1)
forky: resolved (fixed in 4.6-1)
sid: resolved (fixed in 4.6-1)
trixie: resolved (fixed in 4.6-1)
GHSA
GHSA-m3gq-3gw9-x3fv: Libreswan 4
ghsa_unreviewed·2022-01-16
CVE-2022-23094 [HIGH] CWE-476 GHSA-m3gq-3gw9-x3fv: Libreswan 4
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
OSV
CVE-2022-23094: Libreswan 4
osv·2022-01-15·CVSS 7.5
CVE-2022-23094 [HIGH] CVE-2022-23094: Libreswan 4
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/libreswan/libreswan/issues/585https://libreswan.org/security/CVE-2022-23094https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPMIHAXWQUJAPCIGNJ5J5Q6ASWQBU7T5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFZ7WP5LNNBW5ADIOPDSPQ23SXZJRNMP/https://www.debian.org/security/2022/dsa-5048https://github.com/libreswan/libreswan/issues/585https://libreswan.org/security/CVE-2022-23094https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPMIHAXWQUJAPCIGNJ5J5Q6ASWQBU7T5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFZ7WP5LNNBW5ADIOPDSPQ23SXZJRNMP/https://www.debian.org/security/2022/dsa-5048
2022-01-15
Published