Upstream information
Description
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
| CVSS detail | CNA (d42dc95b-23f1-4e06-9076-20753a0fb0df) | National Vulnerability Database |
|---|---|---|
| Base Score | 8.1 | 5.9 |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Attack Vector | Network | Network |
| Attack Complexity | High | High |
| Privileges Required | None | None |
| User Interaction | None | None |
| Scope | Unchanged | Unchanged |
| Confidentiality Impact | High | None |
| Integrity Impact | High | None |
| Availability Impact | High | High |
| CVSSv3 Version | 3.1 | 3.1 |
SUSE Security Advisories:
- RHSA-2026:46396, published Mon Jul 27 15:06:34 UTC 2026
- RHSA-2026:46397, published Mon Jul 27 15:06:34 UTC 2026
- RHSA-2026:46398, published Mon Jul 27 15:06:35 UTC 2026
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Liberty Linux 10 |
| Patchnames: RHSA-2026:46398 |
| SUSE Liberty Linux 8 |
| Patchnames: RHSA-2026:46396 |
| SUSE Liberty Linux 9 |
| Patchnames: RHSA-2026:46397 |
SUSE Timeline for this CVE
CVE page created: Mon Jul 27 14:48:26 2026CVE page last modified: Mon Jul 27 20:33:16 2026