Bug 2501764 (CVE-2026-14957)

Summary: CVE-2026-14957 libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, echaudro, fleitner, jdelft, jupierce, ktraynor, lgarciaa, mbiarnes, paul.wouters, ppalepu, ppostler, prdhamdh, rhel-process-autobot, rkhan, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Libreswan. An unauthenticated remote attacker can send a specially crafted X.509 certificate payload during an IKEv1 or IKEv2 exchange. This flaw occurs when Libreswan is operating in FIPS (Federal Information Processing Standards) mode and processing a certificate with an invalid public key, such as an RSA exponent of zero. This can trigger an assertion failure, leading to the termination of the daemon process and a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2501766    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-17 15:07:27 UTC
Libreswan contains a reachable assertion in the X.509 certificate processing path when operating in FIPS mode. After calling CERT_ExtractPublicKey(), the returned public key is asserted to be non-NULL, although the function may legitimately return NULL if public key extraction fails (for example, when processing a certificate with an RSA exponent of zero). An unauthenticated remote attacker can send a specially crafted CERT payload during an IKEv1 or IKEv2 exchange to trigger the assertion and terminate the daemon, resulting in a denial of service. The issue is only reachable when Libreswan is running in FIPS mode and certificate-based authentication is in use with at least one CA certificate loaded in the Libreswan NSS database; deployments using only Pre-Shared Key (PSK) authentication without loaded CA certificates are not affected.

Comment 4 errata-xmlrpc 2026-07-27 03:11:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:46396 https://access.redhat.com/errata/RHSA-2026:46396

Comment 5 errata-xmlrpc 2026-07-27 03:28:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:46397 https://access.redhat.com/errata/RHSA-2026:46397

Comment 6 errata-xmlrpc 2026-07-27 03:32:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:46398 https://access.redhat.com/errata/RHSA-2026:46398

Comment 7 errata-xmlrpc 2026-07-27 23:28:22 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:46986 https://access.redhat.com/errata/RHSA-2026:46986

Comment 8 errata-xmlrpc 2026-08-17 02:21:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:55449 https://access.redhat.com/errata/RHSA-2026:55449

Comment 9 errata-xmlrpc 2026-08-20 20:50:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:57741 https://access.redhat.com/errata/RHSA-2026:57741

Comment 10 Paul Wouters 2026-08-25 19:53:28 UTC
this bug should be closed

Comment 11 errata-xmlrpc 2026-08-31 04:09:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:61258 https://access.redhat.com/errata/RHSA-2026:61258

Comment 12 errata-xmlrpc 2026-08-31 20:31:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:61779 https://access.redhat.com/errata/RHSA-2026:61779

Comment 13 errata-xmlrpc 2026-09-08 11:26:03 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.20

Via RHSA-2026:63100 https://access.redhat.com/errata/RHSA-2026:63100

Comment 14 errata-xmlrpc 2026-09-08 14:02:38 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.21

Via RHSA-2026:63041 https://access.redhat.com/errata/RHSA-2026:63041

Comment 15 errata-xmlrpc 2026-09-09 09:23:08 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.19

Via RHSA-2026:63044 https://access.redhat.com/errata/RHSA-2026:63044

Comment 16 Jon Orris 2026-09-28 02:26:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:72287 https://access.redhat.com/errata/RHSA-2026:72287