CVE-2018-16151: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verification. Similar to the flaw in the same version of strongSwan regarding digestAlgorithm.parameters, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Strongswan Strongswan: from 4.0.0, up to and including 4.6.4; from 5.0.0, before 5.7.0 (fixed in 5.7.0)

Published 2018-09-26. Last modified 2026-06-17.