Lucene search

K
osvGoogleOSV:RLSA-2022:0199
HistoryJan 19, 2022 - 7:11 p.m.

Important: libreswan security update

2022-01-1919:11:04
Google
osv.dev
10
libreswan
ipsec
ike
linux
security update
cve-2022-23094
cryptography
authentication
encryption
vpn

EPSS

0.02

Percentile

89.1%

Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN).

Security Fix(es):

  • libreswan: Malicious IKEv1 packet can cause libreswan to restart (CVE-2022-23094)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.