CVE Vulnerabilities

CVE-2023-38712

NULL Pointer Dereference

Published: Aug 25, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Libreswan Libreswan 3.0 (including) 4.0 (excluding)
Libreswan Libreswan 4.0 (including) 4.12 (excluding)
Red Hat Enterprise Linux 8 RedHat libreswan-0:4.12-2.el8 *
Red Hat Enterprise Linux 9 RedHat libreswan-0:4.12-1.el9 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat libreswan-0:4.6-3.el9_0.3 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat libreswan-0:4.9-5.el9_2.4 *
Red Hat OpenShift Container Platform 4.15 RedHat libreswan-0:4.6-3.el9_0.3 *
Red Hat OpenShift Container Platform 4.16 RedHat libreswan-0:4.6-3.el9_0.3 *
Red Hat OpenShift Container Platform 4.17 RedHat libreswan-0:4.6-3.el9_0.3 *
Libreswan Ubuntu bionic *
Libreswan Ubuntu focal *
Libreswan Ubuntu lunar *
Libreswan Ubuntu mantic *
Libreswan Ubuntu oracular *
Libreswan Ubuntu trusty *
Libreswan Ubuntu xenial *

Potential Mitigations

References