CVE-2023-38712

Source
https://cve.org/CVERecord?id=CVE-2023-38712
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-38712.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-38712
Downstream
Related
Published
2023-08-25T00:00:00Z
Modified
2026-05-01T04:20:20.813709Z
Summary
[none]
Details

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38712.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/libreswan/libreswan

Affected ranges

Type
GIT
Repo
https://github.com/libreswan/libreswan
Events

Affected versions

v4.*
v4.0
v4.1
v4.10
v4.11
v4.2
v4.3
v4.4
v4.5
v4.6
v4.7
v4.8
v4.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-38712.json"