CVE-2019-10155: Fedoraproject Fedora
Low severity, CVSS 3.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.
Affected products
- Fedoraproject Fedora: version 29 only; version 30 only
- Libreswan Libreswan: before 3.29 (fixed in 3.29)
- Red Hat Enterprise Linux: version 8.0 only
- Strongswan Strongswan: before 5.0.0 (fixed in 5.0.0)
- Xelerance Openswan: any version
Published 2019-06-12. Last modified 2026-06-17.