========================================================================== CVE-2026-94453: IKEv2 Use-After-Free bug when using IKE-over-TCP ========================================================================== Release date: Monday, Oct 5, 2026 Contact: security@libreswan.org PGP key: 907E790F25C1E8E561CD73B585FF4B43B30FC6F9 This alert (and any updates) are available at the following URLs: https://libreswan.org/security/CVE-2026-94453 The Libreswan Project was notified of a Use-After-Free issue when a client connecting using IKE over TCP closes the connection, and another packet (retransmit or malicious) is received for the same tuple. It causes the libreswan IKE daemon pluto to crash and restart. Severity: High Vulnerable versions : 4.0 up to and including 5.4 Not vulnerable : 5.4.1 and 5.3.3 Vulnerability details ===================== IKE state is retained in memory after the client closes the connection storing a pointer to iface_endpoint inside ike_sa.sa->st_iface_endpoint. Once this invalid pointer is used, the daemon crashes. This can happen before the remote peer has authenticated itself. The option for IKE over TCP is not enabled by default. Only configurations that contain listen-tcp=yes are affected. Exploitation ============ Continued triggering of this vulnerability can lead to a denial of service. Remote code execution could be possible. Workaround ========== To temporarily disable IKE over TCP, set listen-tcp=no. History ======= * 16-09-2026 Libreswan was notified of the issue via security@libreswan.org. * 24-09-2026 Advanced notice given to supported customers and distributions. * 05-10-2026 Public announcement and release of libreswan 5.4.1 and 5.3.3. Credits ======= Vlad Miu Upgrading ========= To address this vulnerability, upgrade to libreswan 5.4.1 or 5.3.3. Patches ======= For those who cannot upgrade, patches are available at: https://libreswan.org/security/CVE-2026-94453/ About libreswan (https://libreswan.org/) ======================================== Libreswan is a free implementation of the Internet Key Exchange (IKE) protocols IKEv1 and IKEv2. It is a descendant (continuation fork) of openswan 2.6.38. IKE is used to establish IPsec VPN connections. IPsec uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks. Everything passing through the untrusted network is encrypted by the IPsec gateway machine, and decrypted by the gateway at the other end of the tunnel. The resulting tunnel is a virtual private network (VPN).