Bug 2494149 (CVE-2026-12413)

Summary: CVE-2026-12413 librenswan: IKEv2 Denial of Service via malformed fragmentation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: echaudro, fleitner, ktraynor, rhel-process-autobot, rkhan, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Libreswan's IKEv2 fragment reassembly mechanism. When a VPN gateway processes incoming split network packets (fragments) containing unexpected data, an off-by-one boundary validation error triggers an internal program safety check (assertion failure). A remote, unauthenticated attacker can exploit this by sending a specific sequence of malformed IKEv2 fragments to an exposed gateway, causing the Libreswan daemon to immediately crash and restart. While this flaw does not allow data theft or unauthorized system access, a continuous stream of these packets will lead to a persistent Denial of Service (DoS) for legitimate VPN users.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2494156    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-29 11:30:12 UTC
The Libreswan Project was notified of an issue when it receives an invalidly formatted IKEv2 fragment causing the server to crash and restart. A continued stream of such packets would cause a denial
of service.

Severity : Medium
Vulnerable versions : 4.6 - 5.3
Not vulnerable : 5.3.1 or later