ALAS-2024-587


Amazon Linux 2023 Security Advisory: ALAS-2024-587
Advisory Release Date: 2024-04-10 22:17 Pacific
Advisory Updated Date: 2024-04-15 12:00 Pacific
Severity: Medium

Issue Overview:

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service. (CVE-2024-2357)


Affected Packages:

libreswan


Issue Correction:
Run dnf update libreswan --releasever 2023.4.20240416 to update your system.

New Packages:
aarch64:
    libreswan-debuginfo-4.12-3.amzn2023.0.1.aarch64
    libreswan-4.12-3.amzn2023.0.1.aarch64
    libreswan-debugsource-4.12-3.amzn2023.0.1.aarch64

src:
    libreswan-4.12-3.amzn2023.0.1.src

x86_64:
    libreswan-debuginfo-4.12-3.amzn2023.0.1.x86_64
    libreswan-4.12-3.amzn2023.0.1.x86_64
    libreswan-debugsource-4.12-3.amzn2023.0.1.x86_64