When an IKEv2 state would fail to find its own PreSharedKey (secret) to create the AUTH payload in the IKE_AUTH Exchange, it would omit sending a packet, but would not delete the state. When this state is referenced later, it would cause an assertion failure and crash and restart the pluto daemon. https://libreswan.org/security/CVE-2024-2357 https://github.com/libreswan/libreswan/commit/cb9e1047d33fde695d63a95854c2bc2470a476c8.patch
Created libreswan tracking bugs for this issue: Affects: fedora-all [bug 2269563]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2033 https://access.redhat.com/errata/RHSA-2024:2033
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:2081 https://access.redhat.com/errata/RHSA-2024:2081
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:2085 https://access.redhat.com/errata/RHSA-2024:2085
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2024:2082 https://access.redhat.com/errata/RHSA-2024:2082
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2565 https://access.redhat.com/errata/RHSA-2024:2565