
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50721 is an RSA signature verification flaw in Libreswan's RSA_authenticate_hash_signature_raw_rsa() function that allows unauthenticated remote attackers to forge IKEv1 SIG payloads (impersonation) or trigger a daemon crash (denial of service). It affects all Libreswan versions up to and including 5.3, with version 5.3.1 being the first patched release. The vulnerability was published on July 2, 2026, and is classified as High severity with a CVSS v3.1 base score of 5.9 (per NVD/Feedly) or 8.1 (per GitHub Advisory, which accounts for confidentiality and integrity impacts from impersonation) (GitHub Advisory, Libreswan Advisory).
The root cause is improper verification of cryptographic signature length (CWE-347) combined with a reachable assertion (CWE-617) in the RSA_authenticate_hash_signature_raw_rsa() function. When an IKEv1 SIG payload is encoded using PKCS #1 RSA Encryption (RFC 2313), Libreswan fails to validate that the authentication hash length matches the expected value. This enables two distinct attack paths: (1) a Bleichenbacher-style attack to forge SIG payloads when small RSA public exponents (e.g., e=3) are in use, enabling peer impersonation; and (2) sending a SIG payload with a shorter-than-expected hash to trigger an assertion failure, causing the pluto daemon to abort and restart. X.509 certificate-based verification of remote IKE peers is explicitly not affected by this flaw (GitHub Advisory, Libreswan Advisory).
Successful exploitation can result in two distinct outcomes: impersonation of a legitimate IKE peer (integrity and confidentiality impact) when small RSA public exponents are used, or sustained denial of service via repeated daemon crashes when crafted short-hash SIG payloads are sent. The impersonation vector could allow an attacker to establish unauthorized VPN tunnels, potentially enabling access to protected network segments. Remote code execution is explicitly ruled out by the vendor, and X.509 certificate-based IKE peer verification is unaffected (GitHub Advisory, Libreswan Advisory).
RSA_authenticate_hash_signature_raw_rsa() function triggers an assertion failure, causing the pluto daemon to abort and restart. Repeat to sustain denial of service.pluto daemon crash and restart entries in /var/log/pluto.log or system journal (e.g., pluto[PID]: ABORT or assertion failure messages in RSA_authenticate_hash_signature_raw_rsa); unexpected IKE SA establishment with unfamiliar peer identities.pluto process (Libreswan IKE daemon) visible via systemctl status ipsec or process monitoring tools.Upgrade Libreswan to version 5.3.1 or later, which correctly validates the authentication hash length in RSA_authenticate_hash_signature_raw_rsa() (Libreswan Advisory, GitHub Advisory). As a configuration-based workaround, avoid using small RSA public exponents (e.g., e=3) for IKE peer authentication to eliminate the Bleichenbacher forgery path; use standard exponents (e.g., e=65537). Monitor Libreswan daemon logs for unexpected restarts as an indicator of active exploitation attempts. Patches are tracked for Debian and Ubuntu distributions via their respective security advisories.
The vulnerability was noted in the Solus Linux community weekly update thread for Week 28, 2026, indicating awareness among Linux distribution maintainers. INCIBE-CERT (Spain's national CERT) published an alert for the related CVE-2026-50722. No significant vendor statements beyond the Libreswan project's own advisory or notable researcher commentary have been identified at this time (Libreswan Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."