CVE-2026-12413

Name
CVE-2026-12413
Description
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
d42dc95b-23f1-4e06-9076-20753a0fb0df https://libreswan.org/security/CVE-2026-12413/
d42dc95b-23f1-4e06-9076-20753a0fb0df https://libreswan.org/security/CVE-2026-12413/CVE-2026-12413.txt

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:* libreswan >= 4.6 < 5.3.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libreswan edge-community 5.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libreswan edge-community 5.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libreswan edge-community 5.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libreswan edge-community 5.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libreswan edge-community 4.15-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libreswan edge-community 4.12-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libreswan edge-community 4.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libreswan 3.24-community 5.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable