
🚨High - Libreswan RSA Signature Forgery & DoS in IKE Auth (CVE-2026-50722, CVE-2026-50721) Libreswan improperly verifies RSA PKCS#1 signatures during IKE authentication. In `RSA_authenticate_hash_signature_pkcs1_1_5_rsa()` the IKEv2 AUTH payload's DER-encoded ASN.1 digest isn't correctly checked (RFC 8017 / RSASSA-PKCS1-v1_5), and in `RSA_authenticate_hash_signature_raw_rsa()` the IKEv1 SIG payload's hash length isn't verified (RFC 2313). With small public exponents (e.g. e=3), a remote attacker can use a Bleichenbacher-style attack to forge the AUTH/SIG payload and impersonate a peer. Alternatively, encoding a shorter-than-expected hash triggers a reachable assertion: the `pluto` daemon aborts and restarts, and continued exploitation causes sustained denial of service. No RCE is possible, and X.509 certificate verification of the remote IKE peer is not affected. 👉Fixed in Libreswan `5.3.1` (affects `<= 5.3`).
Post summary
The post discloses two high‑severity Libreswan CVEs allowing RSA signature forgery and a denial‑of‑service via malformed hashes, and indicates the vulnerability is fixed in version 5.3.1.


