Fedora Account System
Red Hat Associate
Red Hat Customer
The Libreswan Project was notified of an issue when it receives an invalidly formatted PKCS#1.5 RSA signature payload that authenticates the IKE exchange. The vulnerability is similar to CVE-2018-16151. Use of RSA signatures over certificates during X.509 certificate verifications of the remote IKE peer are not affected by this vulnerability. When the RSA exponent is weak (eg e=3), Bleichenbacher-style signature forgeries are possible, resulting in an authentication bypass. Note that most cryptographic library versions and libreswan raw RSA key generation have not allowed weak exponents for at least a decade, so valid RSA keys with weak exponents should be very rare. Additionally, the invalid RSA IKE authentication payload can trigger an assertion, resulting in libreswan aborting and restarting. Continued sending of such packets can result in a denial of service. Severity : Medium Vulnerable versions : all version up to and including 5.3 Not vulnerable : 5.3.1 or later
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:46396 https://access.redhat.com/errata/RHSA-2026:46396
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:46397 https://access.redhat.com/errata/RHSA-2026:46397
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:46398 https://access.redhat.com/errata/RHSA-2026:46398
This issue has been addressed in the following products: Fast Datapath for Red Hat Enterprise Linux 9 Via RHSA-2026:46986 https://access.redhat.com/errata/RHSA-2026:46986
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:55449 https://access.redhat.com/errata/RHSA-2026:55449
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:57741 https://access.redhat.com/errata/RHSA-2026:57741
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:61258 https://access.redhat.com/errata/RHSA-2026:61258
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:61779 https://access.redhat.com/errata/RHSA-2026:61779