Description
No description is available for this CVE.
Published: n/a
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malformed X.509 certificate can trigger an assertion failure in the libreswan IPsec daemon. The failure causes the daemon to crash, leading to a loss of availability for any IPsec VPN connections that rely on it. This flaw is characterized as a flow‑control flaw (CWE‑617) stemming from insufficient validation of certificate data, and it manifests as a denial‑of‑service condition for the affected system.

Affected Systems

The flaw affects installations of the libreswan IPsec daemon that accept or process X.509 certificates. Because the affected releases are not specified, any deployment that runs libreswan without the corrective update and performs certificate validation is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.5 denotes a moderate‑to‑high severity vulnerability. With no EPSS score available, a precise measurement of exploitation probability is lacking, but the nature of the defect indicates that remote attackers could exploit it by initiating or injecting a malformed certificate over an externally reachable IPsec interface. The vulnerability is not listed in CISA's KEV catalog, yet it remains a substantial risk for unpatched systems due to its impact on service availability and the possibility of remote exploitation.

Generated by OpenCVE AI on July 30, 2026 at 00:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest libreswan release that incorporates the CVE‑2026‑14957 fix or back‑port the relevant code change.
  • If an immediate update is not feasible, configure the daemon to reject certificates that fail strict validation or restrict acceptable certificates to a trusted CA list.
  • Implement process monitoring (e.g., systemd Restart=on‑failure or a watchdog) so the libreswan process is automatically restarted after a crash, minimizing downtime.

Generated by OpenCVE AI on July 30, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Libreswan
Libreswan libreswan
Vendors & Products Libreswan
Libreswan libreswan

Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process
Weaknesses CWE-617
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Subscriptions

Libreswan Libreswan
cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-15T00:00:00Z

Links: CVE-2026-14957 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T00:45:09Z

Weaknesses