<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:51:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:4050 — Moderate: libreswan security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4050</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libreswan: IKEv1 default AH/ESP responder can crash and restart (CVE-2024-3652)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libreswan: IKEv1 default AH/ESP responder can crash and restart (CVE-2024-3652)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4050</guid>
    </item>
    <item>
      <title>bdu:2024-04885</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04885</link>
      <description>bdu:2024-04885</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04885</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0646 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</link>
      <description>certfr-2024-avi-0646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</guid>
    </item>
    <item>
      <title>EUVD-2026-273650</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-273650</link>
      <description>EUVD-2026-273650</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-273650</guid>
    </item>
    <item>
      <title>fkie_cve-2024-3652</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-3652</link>
      <description>&lt;p&gt;The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan&amp;#39;s default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan&amp;#39;s default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-3652</guid>
    </item>
    <item>
      <title>GHSA-395v-96gv-76w3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-395v-96gv-76w3</link>
      <description>&lt;p&gt;The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan&amp;#39;s default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan&amp;#39;s default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-395v-96gv-76w3</guid>
    </item>
    <item>
      <title>gsd-2024-3652</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-3652</link>
      <description>gsd-2024-3652</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-3652</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-3652 — IKEv1 default AH/ESP responder can cause libreswan to abort and restart</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-3652</link>
      <description>msrc_CVE-2024-3652</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-3652</guid>
    </item>
    <item>
      <title>OESA-2024-1565 — libreswan security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1565</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libreswan, openEuler:20.03-LTS-SP4: libreswan, openEuler:22.03-LTS: libreswan, openEuler:22.03-LTS-SP1: libreswan, openEuler:22.03-LTS-SP2: libreswan, openEuler:22.03-LTS-SP3: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan is an implementation of IKEv1 and IKEv2 for IPsec. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services.  These services allow you to build secure tunnels through untrusted networks.  Everything passing through the untrusted net is encrypted by the ipsec gateway machine and decrypted by the gateway at the other end of the tunnel.  The resulting tunnel is a virtual private network or VPN.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan&amp;amp;apos;s default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.(CVE-2024-3652)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libreswan, openEuler:20.03-LTS-SP4: libreswan, openEuler:22.03-LTS: libreswan, openEuler:22.03-LTS-SP1: libreswan, openEuler:22.03-LTS-SP2: libreswan, openEuler:22.03-LTS-SP3: libreswan&lt;/p&gt;
&lt;p&gt;Libreswan is an implementation of IKEv1 and IKEv2 for IPsec. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services.  These services allow you to build secure tunnels through untrusted networks.  Everything passing through the untrusted net is encrypted by the ipsec gateway machine and decrypted by the gateway at the other end of the tunnel.  The resulting tunnel is a virtual private network or VPN.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan&amp;amp;apos;s default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.(CVE-2024-3652)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1565</guid>
    </item>
    <item>
      <title>RHBA-2024:11505 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.16.28 packages and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:11505</link>
      <description>&lt;p&gt;libreswan: Regression of CVE-2023-30570 fixes in the Red Hat Enterprise Linux libreswan: remote DoS via crafted TS payload with an incorrect selector length libreswan: Malicious IKEv1 Aggressive Mode packets can crash libreswan libreswan: Invalid IKEv2 REKEY proposal causes restart libreswan: Invalid IKEv1 Quick Mode ID causes restart libreswan: Invalid IKEv1 repeat IKE SA delete causes crash and restart libreswan: Missing PreSharedKey for connection can cause crash libreswan: IKEv1 default AH/ESP responder can crash and restart&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libreswan: Regression of CVE-2023-30570 fixes in the Red Hat Enterprise Linux libreswan: remote DoS via crafted TS payload with an incorrect selector length libreswan: Malicious IKEv1 Aggressive Mode packets can crash libreswan libreswan: Invalid IKEv2 REKEY proposal causes restart libreswan: Invalid IKEv1 Quick Mode ID causes restart libreswan: Invalid IKEv1 repeat IKE SA delete causes crash and restart libreswan: Missing PreSharedKey for connection can cause crash libreswan: IKEv1 default AH/ESP responder can crash and restart&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:11505</guid>
    </item>
    <item>
      <title>RHSA-2024:4050 — Red Hat Security Advisory: libreswan security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:4050</link>
      <description>&lt;p&gt;libreswan: IKEv1 default AH/ESP responder can crash and restart&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libreswan: IKEv1 default AH/ESP responder can crash and restart&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:4050</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-3652</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3652</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: libreswan, Ubuntu:20.04:LTS: libreswan, Ubuntu:22.04:LTS: libreswan, Ubuntu:24.04:LTS: libreswan, Ubuntu:25.10: libreswan, Ubuntu:26.04:LTS: libreswan&lt;/p&gt;
&lt;p&gt;The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan&amp;#39;s default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: libreswan, Ubuntu:20.04:LTS: libreswan, Ubuntu:22.04:LTS: libreswan, Ubuntu:24.04:LTS: libreswan, Ubuntu:25.10: libreswan, Ubuntu:26.04:LTS: libreswan&lt;/p&gt;
&lt;p&gt;The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan&amp;#39;s default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3652</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1434 — Red Hat Enterprise Linux (pki and Libreswan): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1434</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1434</guid>
    </item>
  </channel>
</rss>
