Wind River Support Network

HomeDefectsLIN1021-5361
Fixed

LIN1021-5361 : Security Advisory - strongswan - CVE-2023-26463

Created: Mar 2, 2023    Updated: Mar 7, 2023
Resolved Date: Mar 7, 2023
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Fixed a vulnerability related to certificate verification in TLS-based EAP methods that leads to an authentication bypass followed by an expired pointer dereference that results in a denial of service and possibly even remote code  execution.

https://github.com/strongswan/strongswan/commit/ed839b3067566210484fbad879c7e8c9865c940b

CREATE(Triage):(User=admin) CVE-2023-26463 (https://nvd.nist.gov/vuln/detail/CVE-2023-26463)
Live chat
Online