Upstream information

CVE-2024-2357 at MITRE

Description

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v3 Scores
  CNA (CISA-ADP)
Base Score 6.5
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 8
  • libreswan >= 4.12-2.el8_9.2
Patchnames:
RHSA-2024:1998
SUSE Liberty Linux 9
  • libreswan >= 4.12-2.el9_4
Patchnames:
RHSA-2024:2033
RHSA-2024:2565


SUSE Timeline for this CVE

CVE page created: Mon Mar 11 23:00:07 2024
CVE page last modified: Thu Dec 19 11:54:33 2024