Upstream information
Description
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
| CVSS detail | CNA (d42dc95b-23f1-4e06-9076-20753a0fb0df) |
|---|---|
| Base Score | 7.5 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality Impact | None |
| Integrity Impact | None |
| Availability Impact | High |
| CVSSv3 Version | 3.1 |
SUSE Security Advisories:
- RHSA-2026:46396, published Mon Jul 27 15:06:34 UTC 2026
- RHSA-2026:46397, published Mon Jul 27 15:06:34 UTC 2026
- RHSA-2026:46398, published Mon Jul 27 15:06:35 UTC 2026
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Liberty Linux 10 |
| Patchnames: RHSA-2026:46398 |
| SUSE Liberty Linux 8 |
| Patchnames: RHSA-2026:46396 |
| SUSE Liberty Linux 9 |
| Patchnames: RHSA-2026:46397 |
SUSE Timeline for this CVE
CVE page created: Mon Jul 27 14:33:46 2026CVE page last modified: Mon Jul 27 20:26:23 2026