==========================================================================
CVE-2026-77205: Denial of Service via sending bogus X.509 certificates
==========================================================================

Release date: Monday, Oct 5, 2024
Contact: security@libreswan.org
PGP key: 907E790F25C1E8E561CD73B585FF4B43B30FC6F9

This alert (and any updates) are available at the following URLs:
https://libreswan.org/security/CVE-2026-77205


The Libreswan Project received a report about an issue in the libreswan
5.3 series related to badly formed received certificates while running
in FIPS mode. While being rejected, the certifiates were not deleted
from the NSS cache, resulting in any real certificates with the same
serial number being rejected as well. This can be abused to lock out
legitimate peers from connecting.

Severity: Low
Vulnerable versions : 5.3, 5.3.1, 5.3.2
Not vulnerable      : 3.0 - 5.2, 5.4 and higher

Vulnerability details
=====================
The add_decoded_cert() function missed a call to CERT_DestroyCertificate().
This was due to an incorrect fix for CVE-2026-14957, see
https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.txt



Exploitation
============
Sending bogus certificates with new serial numbers could prevent the
real certificates with those serial numbers from connecting until the
service has restarted. While there is no RFC that dictates Certificate
Authority (CA) should use randomized serial numbers, it is considered
best practise and it is a requirement of the CA/Browser Forum. If using
a private Root CA for IPsec VPNs, it is recommended to verify it uses
randomized serial numbers.  However, an attacker could still trick a
peer into connecting to them first, thus learning the serial number.


Workaround
==========
Disabling FIPS mode will prevent this attack vector. If this is not
possible, apply the patch below or upgrade to a later libreswan version.

History
=======
* 30-07-2026 Libreswan was notified of the issue via security@libreswan.org.
* 24-09-2026 Advanced notice given to supported customers and distributions.
* 05-10-2026 Public announcement and release of libreswan 5.3.3.

Credits
=======
Reported by Wojciech Tatarski (TuxCare) <wtatarski@cloudlinux.com

Upgrading
=========
To address this vulnerability, upgrade to libreswan 5.3.3 or later.

Patches
=======
For those who cannot upgrade, patches are available at:
https://libreswan.org/security/CVE-2026-77205/

About libreswan (https://libreswan.org/)
========================================
Libreswan is a free implementation of the Internet Key Exchange (IKE)
protocols IKEv1 and IKEv2. It is a descendant (continuation fork) of
openswan 2.6.38. IKE is used to establish IPsec VPN connections.

IPsec uses strong cryptography to provide both authentication and
encryption services. These services allow you to build secure tunnels
through untrusted networks. Everything passing through the untrusted
network is encrypted by the IPsec gateway machine, and decrypted by
the gateway at the other end of the tunnel. The resulting tunnel is a
virtual private network (VPN).

