- Issued:
- 2019-01-04
- Updated:
- 2019-03-12
RHBA-2019:0490 - Bug Fix Advisory
Synopsis
libreswan bug fix update
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated libreswan packages that fix several bugs are now available for Red Hat Enterprise Linux 7.5 Extended Update Support.
Description
Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN).
This update fixes the following bugs:
- Prior to this update, Libreswan could use deleted objects while printing errors and it also did not properly fail when the AES key size was less than 128 bits. As a consequence, the pluto daemon crashed on assertion failed when the IPsec initiator sent "OAKLEY_KEY_LENGTH == 0 (0x00)" for the AES_CBC encryption algorithm. The error printing has been simplified and the AES key size check has been added to an earlier phase. As a result, Libreswan now correctly handles the described scenario. (BZ#1660535)
- Previously, Libreswan continued to process an IKEv1 packet after it had already processed a delete payload. Consequently, Libreswan had deleted the IKE session state, then tried to read the next payload from that deleted state and crashed. The handling of such packets has been fixed, and Libreswan now correctly stops processing payloads once it processes a delete payload. (BZ#1660541)
- Previously, Libreswan incorrectly passed the zero-length IKEv1 XAUTH password as NULL to the crypt() function. Consequently, Libreswan crashed with the "strncpy(): /usr/libexec/ipsec/pluto killed by 11" message. This has been fixed, and Libreswan now processes IKEv1 empty passwords correctly. (BZ#1664047)
Users of libreswan are advised to upgrade to these updated packages, which fix these bugs.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 7.5 x86_64
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 7.5 s390x
- Red Hat Enterprise Linux for Power, big endian - Extended Update Support 7.5 ppc64
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 7.5 ppc64le
Fixes
- BZ - 1664047 - [abrt] [faf] libreswan: strncpy(): /usr/libexec/ipsec/pluto killed by 11 [rhel-7.5.z]
CVEs
(none)
References
(none)
Red Hat Enterprise Linux for x86_64 - Extended Update Support 7.5
| SRPM | |
|---|---|
| libreswan-3.23-9.el7_5.src.rpm | SHA-256: 76c3d9a54160b7231c66dcb95ac627b7aef3006cbce2bf5a466d0566baeed319 |
| x86_64 | |
| libreswan-3.23-9.el7_5.x86_64.rpm | SHA-256: 462d7cf9818e01ef45f0d3ee40ba77e2358f217dc13c1747e8506df6c76ec81f |
| libreswan-debuginfo-3.23-9.el7_5.x86_64.rpm | SHA-256: 05afef6717c99aeabd90fe262e02a08bc4e5fadf0b8a72e1b54d4cfdbda2232b |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 7.5
| SRPM | |
|---|---|
| libreswan-3.23-9.el7_5.src.rpm | SHA-256: 76c3d9a54160b7231c66dcb95ac627b7aef3006cbce2bf5a466d0566baeed319 |
| s390x | |
| libreswan-3.23-9.el7_5.s390x.rpm | SHA-256: 0fcbb55aac79bf6a567d4ba2d005ea917a86e3d5c3c528ebd8cd99ca15f88d6c |
| libreswan-debuginfo-3.23-9.el7_5.s390x.rpm | SHA-256: 9a7145bfd4f6c93b9e4e3f8143ac85b59614eaecc878c6037f25b9c75e0f59e9 |
Red Hat Enterprise Linux for Power, big endian - Extended Update Support 7.5
| SRPM | |
|---|---|
| libreswan-3.23-9.el7_5.src.rpm | SHA-256: 76c3d9a54160b7231c66dcb95ac627b7aef3006cbce2bf5a466d0566baeed319 |
| ppc64 | |
| libreswan-3.23-9.el7_5.ppc64.rpm | SHA-256: 57ddf0f53fe80082fe89e1dae6b9fa8b107a72276272e16aba5566e199d10010 |
| libreswan-debuginfo-3.23-9.el7_5.ppc64.rpm | SHA-256: c1e893074a6258cac4d98e5170106698c899c339e3378aacbd6d1ffcbfedd30f |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 7.5
| SRPM | |
|---|---|
| libreswan-3.23-9.el7_5.src.rpm | SHA-256: 76c3d9a54160b7231c66dcb95ac627b7aef3006cbce2bf5a466d0566baeed319 |
| ppc64le | |
| libreswan-3.23-9.el7_5.ppc64le.rpm | SHA-256: 129c5eaea5992e732f213e753cef981b350cdc5fb6fe2beb2960f80513c15ef0 |
| libreswan-debuginfo-3.23-9.el7_5.ppc64le.rpm | SHA-256: 93ac7c1e6130436e875782d8b3a540b9eeedc733f336b67899c1910e41e42e12 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.