Debian Security Advisory

DSA-5368-1 libreswan -- security update

Date Reported:
03 Mar 2023
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 1031821.
In Mitre's CVE dictionary: CVE-2023-23009.
More information:

It was discovered that the libreswan IPsec implementation could be forced into a crash/restart via malformed IKEv2 packets after peer authentication, resulting in denial of service.

For the stable distribution (bullseye), this problem has been fixed in version 4.3-1+deb11u3.

We recommend that you upgrade your libreswan packages.

For the detailed security status of libreswan please refer to its security tracker page at: