Resource Exhaustion Affecting libreswan/libreswan package, versions [,4.13)[5.0rc-1,5.0rc-2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.94% (57th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-LIBRESWANLIBRESWAN-6444791
  • published15 Mar 2024
  • disclosed11 Mar 2024
  • creditUnknown

Introduced: 11 Mar 2024

CVE-2024-2357  (opens in a new tab)
CWE-400  (opens in a new tab)

How to fix?

Upgrade libreswan/libreswan to version 4.13, 5.0rc-2 or higher.

Overview

Affected versions of this package are vulnerable to Resource Exhaustion due to a misconfiguration in the handling of PreSharedKeys for IKEv2 connections. An attacker can cause the service to restart under certain retransmit scenarios, leading to repeated crashes, resulting in a denial of service.

Note: This is only exploitable if the connection is automatically added on startup using the auto= keyword.

References

CVSS Base Scores

version 3.1