CVE-2023-2295

HIGH

libreswan - Denial of Service via IKEv1 Aggressive Mode Packet Handling

Title source: llm
STIX 2.1

Description

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

Scores

CVSS v3 7.5
EPSS 0.0140
EPSS Percentile 80.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (9)
libreswan/libreswan 4.9-1.el8
libreswan/libreswan 4.9-1.el9
redhat/enterprise_linux 8.0
redhat/enterprise_linux 9.0
redhat/enterprise_linux_eus 8.8
redhat/enterprise_linux_eus 9.2
redhat/enterprise_linux_server_aus 8.8
redhat/enterprise_linux_server_aus 9.2
redhat/enterprise_linux_server_tus 8.8
Published May 17, 2023
Tracked Since Feb 18, 2026