PT-2026-55315 · Libreswan+1 · Libreswan+1

·

CVE-2026-50721

·

Published

2026-07-02

·

Updated

2026-07-27

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Libreswan (affected versions not specified)
Description Libreswan fails to correctly verify the authentication hash length when the SIG payload of an IKEv1 packet is encoded using PKCS #1 RSA Encryption. This occurs within the RSA authenticate hash signature raw rsa() function. A remote attacker can exploit this using a variation of the Bleichenbacher attack—a cryptographic attack targeting RSA encryption—to forge the SIG payload when small public exponents (such as e=3) are used, potentially leading to impersonation. Furthermore, by encoding a hash shorter than expected in the SIG payload, a remote attacker can trigger an assertion that causes the daemon to abort and restart, resulting in a sustained denial-of-service. Remote code execution is not possible, and X.509 certificate verifications of remote IKE peers remain unaffected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Improper Verification of Cryptographic Signature

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:46396
ALSA-2026:46397
ALSA-2026:46398
AZL-91773
CVE-2026-50721
OESA-2026-2909
OESA-2026-2910
OESA-2026-2911
OESA-2026-2912
OESA-2026-3073
RHSA-2026:46396
RHSA-2026:46397
RHSA-2026:46398
RHSA-2026:46986

Affected Products

Libreswan
Rocky Linux