#1143067 libreswan: CVE-2026-14957

Package:
src:libreswan
Source:
src:libreswan
Submitter:
Salvatore Bonaccorso
Date:
2026-08-08 12:21:03 UTC
Severity:
normal
Tags:
#1143067#5
Date:
2026-07-30 05:24:23 UTC
From:
To:
Hi,

The following vulnerability was published for libreswan.

CVE-2026-14957[0]:
| IPS mode assertion failure malicious CERT payload


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-14957
https://www.cve.org/CVERecord?id=CVE-2026-14957
[1] https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.txt

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143067#14
Date:
2026-08-06 13:50:14 UTC
From:
To:
Dear maintainer,

I've prepared an NMU for libreswan (versioned as 5.2-2.5) and uploaded
it to DELAYED/2. Please feel free to tell me if I should cancel it.

cu
Adrian

#1143067#19
Date:
2026-08-08 12:20:08 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libreswan, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143067@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Adrian Bunk <bunk@debian.org> (supplier of updated libreswan package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 06 Aug 2026 16:04:55 +0300
Source: libreswan
Architecture: source
Version: 5.2-2.5
Distribution: unstable
Urgency: medium
Maintainer: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
Changed-By: Adrian Bunk <bunk@debian.org>
Closes: 1133535 1141390 1143067
Changes:
 libreswan (5.2-2.5) unstable; urgency=medium
 .
   * Non-maintainer upload.
   * Backport upstream fix for FTBFS with GCC 16. (Closes: #1133535)
   * CVE-2026-50721: IKEv1 Denial of Service via RSA-SHA1
     authentication payload
   * CVE-2026-50722: IKEv2 Denial of Service via RSA-SHA1
     authentication payload
   * CVE-2026-12413: IKEv2 Denial of Service via malformed fragmentation
   * (Closes: #1141390)
   * CVE-2026-14957: FIPS mode reachable assertion (Closes: #1143067)
Checksums-Sha1:
 084a62211c96f02316cc00f5b6d190d1018b2ebb 2640 libreswan_5.2-2.5.dsc
 0721c3a88f316023bbe7308c4d88e16509355a05 19076 libreswan_5.2-2.5.debian.tar.xz
Checksums-Sha256:
 0dce4f1152426e3e7c0a6fb73286e53c118e90db49fd8ba321eebce9baccd6b5 2640 libreswan_5.2-2.5.dsc
 69c644a8530d5cd396496688b7347b0c7333d7a8d0baff072cb3990a4a0cc84f 19076 libreswan_5.2-2.5.debian.tar.xz
Files:
 3e1728206c72c7f9cea54de57515eda9 2640 net optional libreswan_5.2-2.5.dsc
 eeb668a51210b152929a779d071ed29f 19076 net optional libreswan_5.2-2.5.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmp1Bj8ACgkQiNJCh6LY
mLH/IxAAk8UnnWhmsHm5umXckSF7TKmYDKKGZ7qCL5svALN6ptdYQGR2HbGNWuR6
yOhFP0a1B7ovl4iP7uwvldNfNSTI+PPYD5qAeIV0H3uW10O+AU/BKBCQWsPlrvfT
EkbpD/+khS4InDvU/Q28Nh5M39ekziwYg5wOH7GrEFcUFx2i5SFidCOjERswBcT3
6gB2algIiZxFhtQSB3OBgDQXPdcCRxDMyVtqWa5if9ScR0zX71jjlCB4jbdPp4sf
iITzIrYbEWUZbU1bnNgU3n+CLZZxRIpniH/C3sQAqtixt5zdxoZZqvtTZ6W3eJTd
BdfUNDejG+3Gih7pZKNxJCdu6vclpTff3rfDuycJfsymIqNGwZuWkX41+IqH/60e
eRdRpzFLg7EeIfYwBjh7Vh1F+jzxUk6+rv+gFXvfWvdNyccFiJ5FAabHviFQFJGa
9cbRVTpJ/jZGkpohNctht6tnRz7kwAwlxRYu50wHh36R6859aUYyhdLUoS/CodEf
SfwCL3LscVuTiRCkGINkVVPyq1cop7eqiTCoYgEczg2eokmfKspicJ/Ja+w3yFAu
t14UMs5uIsjj+VVkD4GpRaf8Xotx8AN9BMMctAeWgoCHwE5Z7q6VJ84xXOStDuqY
d7xbkWPdW943Vt+/xOQ9/AyraEtbG3cguUpZ7F9RiI1oVVKHgvo=
=8n5W
-----END PGP SIGNATURE-----