Upstream information

CVE-2026-12413 at MITRE

Description

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v3 Scores
CVSS detail CNA (d42dc95b-23f1-4e06-9076-20753a0fb0df)
Base Score 7.5
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 10
  • libreswan >= 5.3.2-1.el10_2
  • libreswan-minimal >= 5.3.2-1.el10_2
Patchnames:
RHSA-2026:46398
SUSE Liberty Linux 8
  • libreswan >= 4.12-2.el8_10.6
Patchnames:
RHSA-2026:46396
SUSE Liberty Linux 9
  • libreswan >= 4.15-10.el9_8
Patchnames:
RHSA-2026:46397


SUSE Timeline for this CVE

CVE page created: Mon Jul 27 14:33:46 2026
CVE page last modified: Mon Jul 27 20:26:23 2026