CVE-2022-23094
Published: 15 January 2022
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
Priority
CVSS 3 base score: 7.5
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23094
- https://libreswan.org/security/CVE-2022-23094/CVE-2022-23094.txt
- https://libreswan.org/security/CVE-2022-23094/CVE-2022-23094-libreswan-4.2-4.3.patch (4.2-4.3)
- https://libreswan.org/security/CVE-2022-23094/CVE-2022-23094-libreswan-4.4-4.5.patch (4.4-4.5)
- NVD
- Launchpad
- Debian