CVE-2026-12413

EUVD-2026-41439
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 45.81%
Affected Products (NVD)
VendorProductVersion
libreswanlibreswan
4.6 ≤
𝑥
< 5.3.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libreswan
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
5.2-2.5
fixed
sid
5.2-2.5
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libreswan
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libreswan
RHEL 9
0:4.15-10.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libreswan
Amazon Linux 2023
0:4.12-3.amzn2023.0.3
fixed
libreswan-debuginfo
Amazon Linux 2023
0:4.12-3.amzn2023.0.3
fixed
libreswan-debugsource
Amazon Linux 2023
0:4.12-3.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
libreswan
Azure Linux 3.0
0:4.15-2.azl3
fixed