| Summary: | libreswan new security issue CVE-2024-2357 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Nicolas Salguero <nicolas.salguero> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, herman.viaene, sysadmin-bugs |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA9-64-OK | ||
| Source RPM: | libreswan-4.12-1.mga9.src.rpm | CVE: | CVE-2024-2357 |
| Status comment: | |||
|
Description
Nicolas Salguero
2024-03-21 16:35:25 CET
Nicolas Salguero
2024-03-21 16:50:36 CET
Status comment:
(none) =>
Fixed upstream in 4.13 and patch available from upsteam You look after this, Stig. Assignee:
bugsquad =>
smelror Suggested advisory: ======================== The updated package fixes a security vulnerability: The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service. (CVE-2024-2357) References: https://libreswan.org/security/CVE-2024-2357/CVE-2024-2357.txt ======================== Updated package in core/updates_testing: ======================== libreswan-4.14-1.mga9 from SRPM: libreswan-4.14-1.mga9.src.rpm Status comment:
Fixed upstream in 4.13 and patch available from upsteam =>
(none)
katnatek
2024-04-03 19:49:12 CEST
Keywords:
(none) =>
advisory MGA9-64 Plasma Wayland on HP-Pavillion No installation issues Ref bug 31865 for testing. Installation nor removing libreswan does not affect my internal networking nor access to the internet. OK for me. Whiteboard:
(none) =>
MGA9-64-OK Validating. CC:
(none) =>
andrewsfarm, sysadmin-bugs An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0113.html Status:
ASSIGNED =>
RESOLVED |