Fedora Account System
Red Hat Associate
Red Hat Customer
Libreswan contains a reachable assertion in the X.509 certificate processing path when operating in FIPS mode. After calling CERT_ExtractPublicKey(), the returned public key is asserted to be non-NULL, although the function may legitimately return NULL if public key extraction fails (for example, when processing a certificate with an RSA exponent of zero). An unauthenticated remote attacker can send a specially crafted CERT payload during an IKEv1 or IKEv2 exchange to trigger the assertion and terminate the daemon, resulting in a denial of service. The issue is only reachable when Libreswan is running in FIPS mode and certificate-based authentication is in use with at least one CA certificate loaded in the Libreswan NSS database; deployments using only Pre-Shared Key (PSK) authentication without loaded CA certificates are not affected.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:46396 https://access.redhat.com/errata/RHSA-2026:46396
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:46397 https://access.redhat.com/errata/RHSA-2026:46397
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:46398 https://access.redhat.com/errata/RHSA-2026:46398
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 9 Via RHSA-2026:46986 https://access.redhat.com/errata/RHSA-2026:46986
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:55449 https://access.redhat.com/errata/RHSA-2026:55449
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:57741 https://access.redhat.com/errata/RHSA-2026:57741
this bug should be closed
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:61258 https://access.redhat.com/errata/RHSA-2026:61258
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:61779 https://access.redhat.com/errata/RHSA-2026:61779
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.20 Via RHSA-2026:63100 https://access.redhat.com/errata/RHSA-2026:63100
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.21 Via RHSA-2026:63041 https://access.redhat.com/errata/RHSA-2026:63041
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:63044 https://access.redhat.com/errata/RHSA-2026:63044