CVE-2024-2357: The Libreswan Project Www.libreswan.org Libreswan
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.
Affected products
- The Libreswan Project Www.libreswan.org Libreswan: from 4.2, up to and including 4.12
Published 2024-03-11. Last modified 2026-06-17.