<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:54:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:0199 — Important: libreswan security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:0199</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libreswan: Malicious IKEv1 packet can cause libreswan to restart (CVE-2022-23094)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libreswan: Malicious IKEv1 packet can cause libreswan to restart (CVE-2022-23094)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:0199</guid>
    </item>
    <item>
      <title>cnvd-2022-15522</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-15522</link>
      <description>cnvd-2022-15522</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-15522</guid>
    </item>
    <item>
      <title>EUVD-2026-13708</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-13708</link>
      <description>EUVD-2026-13708</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-13708</guid>
    </item>
    <item>
      <title>fkie_cve-2022-23094</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23094</link>
      <description>&lt;p&gt;Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-23094</guid>
    </item>
    <item>
      <title>GHSA-m3gq-3gw9-x3fv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m3gq-3gw9-x3fv</link>
      <description>&lt;p&gt;Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m3gq-3gw9-x3fv</guid>
    </item>
    <item>
      <title>gsd-2022-23094</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-23094</link>
      <description>gsd-2022-23094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-23094</guid>
    </item>
    <item>
      <title>OESA-2022-1738 — libreswan security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1738</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan is an implementation of IKEv1 and IKEv2 for IPsec. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services.  These services allow you to build secure tunnels through untrusted networks.  Everything passing through the untrusted net is encrypted by the ipsec gateway machine and decrypted by the gateway at the other end of the tunnel.  The resulting tunnel is a virtual private network or VPN.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.(CVE-2022-23094)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan is an implementation of IKEv1 and IKEv2 for IPsec. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services.  These services allow you to build secure tunnels through untrusted networks.  Everything passing through the untrusted net is encrypted by the ipsec gateway machine and decrypted by the gateway at the other end of the tunnel.  The resulting tunnel is a virtual private network or VPN.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.(CVE-2022-23094)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1738</guid>
    </item>
    <item>
      <title>RHSA-2022:0199 — Red Hat Security Advisory: libreswan security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0199</link>
      <description>&lt;p&gt;libreswan: Malicious IKEv1 packet can cause libreswan to restart&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libreswan: Malicious IKEv1 packet can cause libreswan to restart&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0199</guid>
    </item>
    <item>
      <title>RHSA-2022:0239 — Red Hat Security Advisory: libreswan security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0239</link>
      <description>&lt;p&gt;libreswan: Malicious IKEv1 packet can cause libreswan to restart&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libreswan: Malicious IKEv1 packet can cause libreswan to restart&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0239</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-23094</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23094</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: libreswan, Ubuntu:20.04:LTS: libreswan, Ubuntu:22.04:LTS: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: libreswan, Ubuntu:20.04:LTS: libreswan, Ubuntu:22.04:LTS: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23094</guid>
    </item>
  </channel>
</rss>
