VYPR
High severity7.5NVD Advisory· Published May 24, 2019· Updated Jun 17, 2026

CVE-2019-12312

CVE-2019-12312

Description

In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IKEv2 IKE_SA_INIT exchange, followed by a bogus INFORMATIONAL exchange instead of the normallly expected IKE_AUTH exchange. This affects send_v2N_spi_response_from_state() in programs/pluto/ikev2_send.c that will then trigger a NULL pointer dereference leading to a restart of libreswan.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*range: <3.28
    • (no CPE)range: <3.27
  • Libreswan/Libreswandescription

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.