Bug 32996 - libreswan new security issue CVE-2024-2357
Summary: libreswan new security issue CVE-2024-2357
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-03-21 16:35 CET by Nicolas Salguero
Modified: 2024-04-07 00:17 CEST (History)
3 users (show)

See Also:
Source RPM: libreswan-4.12-1.mga9.src.rpm
CVE: CVE-2024-2357
Status comment:


Attachments

Description Nicolas Salguero 2024-03-21 16:35:25 CET
Upstream have released a patch to fix CVE-2024-2357:
https://libreswan.org/security/CVE-2024-2357/CVE-2024-2357.txt

Fixed in version 4.13+.

Mageia 9 is also affected.
Nicolas Salguero 2024-03-21 16:50:36 CET

Status comment: (none) => Fixed upstream in 4.13 and patch available from upsteam
CVE: (none) => CVE-2024-2357
Source RPM: (none) => libreswan-4.12-1.mga10.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 1 Lewis Smith 2024-03-22 21:46:24 CET
You look after this, Stig.

Assignee: bugsquad => smelror

Comment 2 Nicolas Salguero 2024-04-03 15:16:10 CEST
Suggested advisory:
========================

The updated package fixes a security vulnerability:

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service. (CVE-2024-2357)

References:
https://libreswan.org/security/CVE-2024-2357/CVE-2024-2357.txt
========================

Updated package in core/updates_testing:
========================
libreswan-4.14-1.mga9

from SRPM:
libreswan-4.14-1.mga9.src.rpm

Status comment: Fixed upstream in 4.13 and patch available from upsteam => (none)
Whiteboard: MGA9TOO => (none)
Source RPM: libreswan-4.12-1.mga10.src.rpm => libreswan-4.12-1.mga9.src.rpm
Assignee: smelror => qa-bugs
Version: Cauldron => 9
Status: NEW => ASSIGNED

katnatek 2024-04-03 19:49:12 CEST

Keywords: (none) => advisory

Comment 3 Herman Viaene 2024-04-05 15:16:23 CEST
MGA9-64 Plasma Wayland on HP-Pavillion
No installation issues
Ref bug 31865 for testing. Installation nor removing libreswan does not affect my internal networking nor access to the internet.
OK for me.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2024-04-06 00:06:57 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 5 Mageia Robot 2024-04-07 00:17:50 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0113.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.