==========================================================================
CVE-2026-94453: IKEv2 Use-After-Free bug when using IKE-over-TCP
==========================================================================

Release date: Monday, Oct 5, 2024
Contact: security@libreswan.org
PGP key: 907E790F25C1E8E561CD73B585FF4B43B30FC6F9

This alert (and any updates) are available at the following URLs:
https://libreswan.org/security/CVE-2026-94453



The Libreswan Project was notified of a Use-After-Free issue when a
client connecting using IKE over TCP closes the connection, and another
packet (retransmit or malicious) is received for the same tuple. It
causes the libreswan IKE daemon pluto to crash and restart.

Severity: High
Vulnerable versions : 4.0 up to and including 5.4
Not vulnerable      : 5.4.1 and 5.3.3

Vulnerability details
=====================
IKE state is retained in memory after the client closes the connection storing
a pointer to iface_endpoint inside ike_sa.sa->st_iface_endpoint. Once this
invalid pointer is used, the daemon crashes. This can happen before the remote
peer has authenticated itself.
The option for IKE over TCP is not enabled by default. Only configurations that
contain listen-tcp=yes are affected.


Exploitation
============
Continued triggering of this vulnerability can lead to a denial of service.
Remote code execution could be possible.


Workaround
==========
To temporarily disable IKE over TCP, set listen-tcp=no.

History
=======
* 16-09-2026 Libreswan was notified of the issue via security@libreswan.org.
* 24-09-2026 Advanced notice given to supported customers and distributions.
* 05-10-2026 Public announcement and release of libreswan 5.4.1 and 5.3.3.

Credits
=======
Vlad Miu <miuvlad62@gmail.com>

Upgrading
=========
To address this vulnerability, upgrade to libreswan 5.4.1 or 5.3.3.

Patches
=======
For those who cannot upgrade, patches are available at:
https://libreswan.org/security/CVE-2026-94453/

About libreswan (https://libreswan.org/)
========================================
Libreswan is a free implementation of the Internet Key Exchange (IKE)
protocols IKEv1 and IKEv2. It is a descendant (continuation fork) of
openswan 2.6.38. IKE is used to establish IPsec VPN connections.

IPsec uses strong cryptography to provide both authentication and
encryption services. These services allow you to build secure tunnels
through untrusted networks. Everything passing through the untrusted
network is encrypted by the IPsec gateway machine, and decrypted by
the gateway at the other end of the tunnel. The resulting tunnel is a
virtual private network (VPN).
