Lucene search

K
osvGoogleOSV:ALSA-2022:0199
HistoryJan 19, 2022 - 7:11 p.m.

Important: libreswan security update

2022-01-1919:11:04
Google
osv.dev
11
libreswan
security update
ipsec
ike
linux
cryptography
authentication
encryption
vpn
cve-2022-23094

EPSS

0.02

Percentile

89.1%

Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN).

Security Fix(es):

  • libreswan: Malicious IKEv1 packet can cause libreswan to restart (CVE-2022-23094)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.