Bug 33105 - libreswan CVE-2024-3652
Summary: libreswan CVE-2024-3652
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-04-17 05:39 CEST by Stig-Ørjan Smelror
Modified: 2024-04-19 03:17 CEST (History)
2 users (show)

See Also:
Source RPM:
CVE: CVE-2024-3652
Status comment:


Attachments

Description Stig-Ørjan Smelror 2024-04-17 05:39:01 CEST
The libreswan team have released version 4.15 to fix CVE-2024-3652.

https://github.com/advisories/GHSA-395v-96gv-76w3
Comment 1 Stig-Ørjan Smelror 2024-04-17 05:39:28 CEST
Cauldron updated

CVE: (none) => CVE-2024-3652

Comment 2 Stig-Ørjan Smelror 2024-04-17 06:11:43 CEST
Advisory
========

libreswan has been updated to version 4.15 to fix CVE-2024-3652.

CVE-2024-3652: The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.


References
==========
https://github.com/advisories/GHSA-395v-96gv-76w3
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3652


Files
=====

Uploaded to core/updates_testing

libreswan-4.15-1.mga9

from libreswan-4.15-1.mga9.src.rpm

Assignee: smelror => qa-bugs

katnatek 2024-04-18 04:44:39 CEST

Keywords: (none) => advisory

Comment 3 katnatek 2024-04-18 04:51:23 CEST
RH mageia 9 x86_64

LC_ALL=C urpmi libreswan
To satisfy dependencies, the following packages are going to be installed:
  Package                        Version      Release       Arch    
(medium "Core Release (distrib1)")
  lib64ldns3                     1.8.3        1.mga9        x86_64  
(medium "Core Updates (distrib3)")
  libreswan                      4.14         1.mga9        x86_64  
4.8MB of additional disk space will be used.
1.3MB of packages will be retrieved.
Proceed with the installation of the 2 packages? (Y/n) y


    https://mirror.math.princeton.edu/pub/mageia/distrib/9/x86_64/media/core/release/lib64ldns3-1.8.3-1.mga9.x86_64.rpm
    https://mirror.math.princeton.edu/pub/mageia/distrib/9/x86_64/media/core/updates/libreswan-4.14-1.mga9.x86_64.rpm               
installing libreswan-4.14-1.mga9.x86_64.rpm lib64ldns3-1.8.3-1.mga9.x86_64.rpm from /var/cache/urpmi/rpms                           
Preparing...                     ##################################################################################################
      1/2: lib64ldns3            ##################################################################################################
      2/2: libreswan             ##################################################################################################

LC_ALL=C urpmi --auto --auto-update 
medium "QA Testing (32-bit)" is up-to-date
medium "QA Testing (64-bit)" is up-to-date
medium "Core Release (distrib1)" is up-to-date
medium "Core Updates (distrib3)" is up-to-date
medium "Nonfree Release (distrib11)" is up-to-date
medium "Nonfree Updates (distrib13)" is up-to-date
medium "Tainted Release (distrib21)" is up-to-date
medium "Tainted Updates (distrib23)" is up-to-date
medium "Core 32bit Release (distrib31)" is up-to-date
medium "Core 32bit Updates (distrib32)" is up-to-date
medium "Nonfree 32bit Release (distrib36)" is up-to-date
medium "Tainted 32bit Release (distrib41)" is up-to-date
medium "Tainted 32bit Updates (distrib42)" is up-to-date


installing libreswan-4.15-1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: libreswan             ##################################################################################################
      1/1: removing libreswan-4.14-1.mga9.x86_64
                                 ##################################################################################################


urpmq --whatrequires-recursive libreswan
libreswan
libreswan

LC_ALL=C urpme libreswan
removing libreswan-4.15-1.mga9.x86_64
removing package libreswan-4.15-1.mga9.x86_64
      1/1: removing libreswan-4.15-1.mga9.x86_64
                                 ##################################################################################################
katnatek 2024-04-18 19:40:23 CEST

CC: (none) => andrewsfarm

Comment 4 katnatek 2024-04-18 19:41:56 CEST
A little complex/time-consuming test this, give ok

Whiteboard: (none) => MGA9-64-OK

Comment 5 Thomas Andrews 2024-04-18 20:33:55 CEST
Previous updates were validated essentially after a clean install that didn't appear to do any harm.

Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 6 Mageia Robot 2024-04-19 03:17:29 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0138.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.