[ALSA-2026:46397] Important: libreswan security update
Type:
security
Severity:
important
Release date:
2026-07-27
Description:
Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN). Security Fix(es): * librenswan: IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload (CVE-2026-50721) * librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload (CVE-2026-50722) * librenswan: IKEv2 Denial of Service via malformed fragmentation (CVE-2026-12413) * libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process (CVE-2026-14957) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libreswan-4.15-10.el9_8.aarch64.rpm 7fbd48ff475d04b36d0cf46b6ac825e7166829d3e733ab6d2d1619a3166f413f
ppc64le libreswan-4.15-10.el9_8.ppc64le.rpm 830e17415767f30c35bcf2b6b57653a5cfb1cda37a4ec954e4c23af187564677
s390x libreswan-4.15-10.el9_8.s390x.rpm 77fb0935cec3734cd8cb85613bb81a15ced5da2c13837b9f1120e372536011fc
x86_64 libreswan-4.15-10.el9_8.x86_64.rpm 162383871b2d8b391ac06f55945c85b2a5788b346d9659c4b935143ab313bc4f
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.