Bug 2494148 (CVE-2026-50722) - CVE-2026-50722 librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload
Summary: CVE-2026-50722 librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASS...
Keywords:
Status: NEW
Alias: CVE-2026-50722
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2494155
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-29 11:30 UTC by OSIDB Bzimport
Modified: 2026-08-31 20:31 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:46396 0 None None None 2026-07-27 03:11:26 UTC
Red Hat Product Errata RHSA-2026:46397 0 None None None 2026-07-27 03:28:32 UTC
Red Hat Product Errata RHSA-2026:46398 0 None None None 2026-07-27 03:32:20 UTC
Red Hat Product Errata RHSA-2026:46986 0 None None None 2026-07-27 23:28:21 UTC
Red Hat Product Errata RHSA-2026:55449 0 None None None 2026-08-17 02:21:50 UTC
Red Hat Product Errata RHSA-2026:57741 0 None None None 2026-08-20 20:50:24 UTC
Red Hat Product Errata RHSA-2026:61258 0 None None None 2026-08-31 04:09:19 UTC
Red Hat Product Errata RHSA-2026:61779 0 None None None 2026-08-31 20:31:11 UTC

Description OSIDB Bzimport 2026-06-29 11:30:10 UTC
The Libreswan Project was notified of an issue when it receives an invalidly formatted PKCS#1.5 RSA signature payload that authenticates the IKE exchange. The vulnerability is similar to CVE-2018-16151.
Use of RSA signatures over certificates during X.509 certificate verifications of the remote IKE peer are not affected by this vulnerability.

When the RSA exponent is weak (eg e=3), Bleichenbacher-style signature forgeries are possible, resulting in an authentication bypass. Note that most cryptographic library versions and libreswan raw RSA key generation have not allowed weak exponents for at least a decade, so valid RSA keys with weak exponents should be very rare.

Additionally, the invalid RSA IKE authentication payload can trigger an assertion, resulting in libreswan aborting and restarting. Continued sending of such packets can result in a denial of service.

Severity : Medium
Vulnerable versions : all version up to and including 5.3
Not vulnerable : 5.3.1 or later

Comment 2 errata-xmlrpc 2026-07-27 03:11:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:46396 https://access.redhat.com/errata/RHSA-2026:46396

Comment 3 errata-xmlrpc 2026-07-27 03:28:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:46397 https://access.redhat.com/errata/RHSA-2026:46397

Comment 4 errata-xmlrpc 2026-07-27 03:32:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:46398 https://access.redhat.com/errata/RHSA-2026:46398

Comment 5 errata-xmlrpc 2026-07-27 23:28:19 UTC
This issue has been addressed in the following products:

  Fast Datapath for Red Hat Enterprise Linux 9

Via RHSA-2026:46986 https://access.redhat.com/errata/RHSA-2026:46986

Comment 6 errata-xmlrpc 2026-08-17 02:21:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:55449 https://access.redhat.com/errata/RHSA-2026:55449

Comment 7 errata-xmlrpc 2026-08-20 20:50:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:57741 https://access.redhat.com/errata/RHSA-2026:57741

Comment 8 errata-xmlrpc 2026-08-31 04:09:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:61258 https://access.redhat.com/errata/RHSA-2026:61258

Comment 9 errata-xmlrpc 2026-08-31 20:31:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:61779 https://access.redhat.com/errata/RHSA-2026:61779


Note You need to log in before you can comment on or make changes to this bug.