CVE-2018-16151: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verification. Similar to the flaw in the same version of strongSwan regarding digestAlgorithm.parameters, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Strongswan Strongswan: from 4.0.0, up to and including 4.6.4; from 5.0.0, before 5.7.0 (fixed in 5.7.0)
Published 2018-09-26. Last modified 2026-06-17.