CVE-2023-23009: Debian Linux

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Libreswan Libreswan: version 4.9 only

Published 2023-02-21. Last modified 2026-06-17.