{"id":"CVE-2022-23094","details":"Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.","modified":"2026-08-12T03:51:11.257971896Z","published":"2022-01-15T01:37:32Z","related":["ALSA-2022:0199"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23094.json"},"references":[{"type":"WEB","url":"https://libreswan.org/security/CVE-2022-23094"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23094.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPMIHAXWQUJAPCIGNJ5J5Q6ASWQBU7T5/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFZ7WP5LNNBW5ADIOPDSPQ23SXZJRNMP/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23094"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5048"},{"type":"REPORT","url":"https://github.com/libreswan/libreswan/issues/585"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libreswan/libreswan","events":[{"introduced":"89eab903b8447af72293271f42b14cb30bd69dac"},{"fixed":"f36ab1b1dfec296b96985c52f8b6729463b7435e"}],"database_specific":{"cpe":"cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.2"},{"fixed":"4.5"},{"fixed":"4.6"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["v4.4","v4.3","v4.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23094.json"}}],"schema_version":"1.9.0"}