CVE Published: 11/03/2024 |
CVE Updated: 20/11/2024 |
CVE Year: 2024 Source: libreswan |
Vendor: The Libreswan Project (www.libreswan.org) |
Product: libreswan Status : PUBLISHED
CVE-2024-2357 Description
The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.