========================================================================== CVE-2026-77206: IKEv2 pre-authentication Null Pointer deref in EAP code ========================================================================== Release date: Monday, Oct 5, 2026 Contact: security@libreswan.org PGP key: 907E790F25C1E8E561CD73B585FF4B43B30FC6F9 This alert (and any updates) are available at the following URLs: https://libreswan.org/security/CVE-2026-77206 The Libreswan Project was informed of a Null Pointer Dereference bug in the EAP handling code for authentication that can result in a denial of service against the libreswan pluto daemon. Severity: Medium Vulnerable versions : 4.7 - 5.4 Not vulnerable : 5.3.3, 5.4.1 Vulnerability details ===================== As a result of inconsistency within the IKEv2 state machine code, a bug can be triggered by any IKEv2 connection, even if EAP is not configured at all. The bug results in a crash and restart. No remote code execution is possible. The error is caused by a fall-through error where it incorrectly dereferences ike->sa.st_eap which is NULL. Exploitation ============ An malicious IKE_AUTH packet can trigger this bug, meaning the peer need not be authenticated. Continued attempts to use IKEv2 with such malicious payloads can cause a denial of service. No remote code execution is possible. Workaround ========== Apply the patch below or upgrade to a supported version. History ======= * 05-08-2026 Libreswan was notified of the issue via security@libreswan.org. * 24-09-2026 Advanced notice given to supported customers and distributions. * 05-10-2026 Public announcement and release of libreswan 5.4.1 and 5.3.3. Credits ======= Claude by Anthropic, as reported by David Korczynski from ADA Logics Ltd. Upgrading ========= To address this vulnerability, upgrade to libreswan 5.3.3, 5.4.1 or later. Note that EAP was not functional in libreswan 5.3. If you need EAP support, use 5.4.1 oe later. Patches ======= For those who cannot upgrade, patches are available at: https://libreswan.org/security/CVE-2026-77206/ About libreswan (https://libreswan.org/) ======================================== Libreswan is a free implementation of the Internet Key Exchange (IKE) protocols IKEv1 and IKEv2. It is a descendant (continuation fork) of openswan 2.6.38. IKE is used to establish IPsec VPN connections. IPsec uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks. Everything passing through the untrusted network is encrypted by the IPsec gateway machine, and decrypted by the gateway at the other end of the tunnel. The resulting tunnel is a virtual private network (VPN).