{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*",
            "extracted_events": [
              {
                "introduced": "4.6"
              },
              {
                "fixed": "5.3.1"
              }
            ],
            "source": "CPE_RANGE"
          },
          "events": [
            {
              "introduced": "5cb4ea71800792204de69a9f546ca6a41f377bf3"
            },
            {
              "fixed": "de24519eb4ff49803a21d75e880c87834cf33beb"
            }
          ],
          "repo": "https://github.com/libreswan/libreswan",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {},
  "details": "An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md-\u003edigest_roof \u003c elemsof(md-\u003edigest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.",
  "id": "CVE-2026-12413",
  "modified": "2026-07-10T03:54:32.227559406Z",
  "published": "2026-07-02T22:16:42.517Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://libreswan.org/security/CVE-2026-12413/"
    },
    {
      "type": "ADVISORY",
      "url": "https://libreswan.org/security/CVE-2026-12413/CVE-2026-12413.txt"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}