
🚨High - Libreswan pluto IKEv2 Fragment DoS via Off-by-One Assertion (CVE-2026-12413) An invalidly formatted IKEv2 fragment crashes Libreswan's pluto daemon. reassemble_v2_incoming_fragments() ignores unknown outer payloads but still stores them in the fixed-size msg_digest.digest[PAYLIMIT] array, and an off-by-one in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) makes the daemon abort. The daemon crashes, and restarts, and repeated packets create a persistent denial of service that drops IPsec VPN tunnels. No RCE is possible. Any config allowing IKEv2 connections that don't set fragmentation=no is affected; IKEv1 is not. 👉Upgrade Libreswan to 5.3.1.
Post summary
A high‑severity off‑by‑one denial‑of‑service vulnerability (CVE‑2026‑12413) in Libreswan's pluto daemon is disclosed with detailed technical context, and users are advised to upgrade to version 5.3.1 to remediate the issue.


