- What: Security update for libreswan
- Impact: Red Hat Enterprise Linux 9.4 systems
Red Hat Product Errata RHSA-2026:61258 - Security Advisory Issued: 2026-08-31 Updated: 2026-08-31 RHSA-2026:61258 - Security Advisory Overview Updated Packages Synopsis Important: libreswan security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libreswan is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN). Security Fix(es): librenswan: IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload (CVE-2026-50721) librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload (CVE-2026-50722) librenswan: IKEv2 Denial of Service via malformed fragmentation (CVE-2026-12413) libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process (CVE-2026-14957) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2494147 - CVE-2026-50721 librenswan: IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload BZ - 2494148 - CVE-2026-50722 librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload BZ - 2494149 - CVE-2026-12413 librenswan: IKEv2 Denial of Service via malformed fragmentation BZ - 2501764 - CVE-2026-14957 libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process CVEs CVE-2026-12413 CVE-2026-14957 CVE-2026-50721 CVE-2026-50722 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM libreswan-4.12-3.el9_4.2.src.rpm SHA-256: 1d2b9028bb4c8790c7df3947ddb5ca512028cd84785dad39126aeb72d9a4a887 x86_64 libreswan-4.12-3.el9_4.2.x86_64.rpm SHA-256: 6f03e472c801ecd0bc0ef73963ed11b495f8cb88ef4ee2d36f22729c7f01420f libreswan-debuginfo-4.12-3.el9_4.2.x86_64.rpm SHA-256: 0c6580ce0079c50f18fa501f1468b680be6b2c63a81236262e872c29f7752222 libreswan-debugsource-4.12-3.el9_4.2.x86_64.rpm SHA-256: 7720de8c1055318c39acd6c6c46dc9d816ed003a1f1b7b300e65291c29bc35ac Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM libreswan-4.12-3.el9_4.2.src.rpm SHA-256: 1d2b9028bb4c8790c7df3947ddb5ca512028cd84785dad39126aeb72d9a4a887 ppc64le libreswan-4.12-3.el9_4.2.ppc64le.rpm SHA-256: 04e75c7abe958fcb33447d43e53153b55d58f1215e8753ea4678de18251cf2fd libreswan-debuginfo-4.12-3.el9_4.2.ppc64le.rpm SHA-256: 548c1db56aab5fea262b6f55340c220432e81e49aa926a8b0b0fb811e63a4bc6 libreswan-debugsource-4.12-3.el9_4.2.ppc64le.rpm SHA-256: 998ffced630ec3e19f700e421764e3741752a61adff805819b3cc24c341fb8c6 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM libreswan-4.12-3.el9_4.2.src.rpm SHA-256: 1d2b9028bb4c8790c7df3947ddb5ca512028cd84785dad39126aeb72d9a4a887 x86_64 libreswan-4.12-3.el9_4.2.x86_64.rpm SHA-256: 6f03e472c801ecd0bc0ef73963ed11b495f8cb88ef4ee2d36f22729c7f01420f libreswan-debuginfo-4.12-3.el9_4.2.x86_64.rpm SHA-256: 0c6580ce0079c50f18fa501f1468b680be6b2c63a81236262e872c29f7752222 libreswan-debugsource-4.12-3.el9_4.2.x86_64.rpm SHA-256: 7720de8c1055318c39acd6c6c46dc9d816ed003a1f1b7b300e65291c29bc35ac Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM libreswan-4.12-3.el9_4.2.src.rpm SHA-256: 1d2b9028bb4c8790c7df3947ddb5ca512028cd84785dad39126aeb72d9a4a887 aarch64 libreswan-4.12-3.el9_4.2.aarch64.rpm SHA-256: 45aa7cfa698d9c2315341a4d8465a33202973e83f24a7400c0fcadec9091b0a6 libreswan-debuginfo-4.12-3.el9_4.2.aarch64.rpm SHA-256: 919d54f02d0745c2cdddbb870249b4ed0013725a563e4a7d77623cecaf7966ad libreswan-debugsource-4.12-3.el9_4.2.aarch64.rpm SHA-256: b675c90b3448291e34a14559537971a5c4c05a190a61185fa9402562bd82485b Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM libreswan-4.12-3.el9_4.2.src.rpm SHA-256: 1d2b9028bb4c8790c7df3947ddb5ca512028cd84785dad39126aeb72d9a4a887 s390x libreswan-4.12-3.el9_4.2.s390x.rpm SHA-256: f4466266611ab7ff05cfc9e4203ea8871859db1d324af3ec806cdd33be0b173e libreswan-debuginfo-4.12-3.el9_4.2.s390x.rpm SHA-256: 582ade82ab7e43c98aece120ac894475d0c7a59fcad4c60c91c5b410a676c594 libreswan-debugsource-4.12-3.el9_4.2.s390x.rpm SHA-256: 7063ad3d09d58c9c05a00897dc748c39bdd0746b1c540158fff7a150c7576d0e Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SRPM libreswan-4.12-3.el9_4.2.src.rpm SHA-256: 1d2b9028bb4c8790c7df3947ddb5ca512028cd84785dad39126aeb72d9a4a887 x86_64 libreswan-4.12-3.el9_4.2.x86_64.rpm SHA-256: 6f03e472c801ecd0bc0ef73963ed11b495f8cb88ef4ee2d36f22729c7f01420f libreswan-debuginfo-4.12-3.el9_4.2.x86_64.rpm SHA-256: 0c6580ce0079c50f18fa501f1468b680be6b2c63a81236262e872c29f7752222 libreswan-debugsource-4.12-3.el9_4.2.x86_64.rpm SHA-256: 7720de8c1055318c39acd6c6c46dc9d816ed003a1f1b7b300e65291c29bc35ac Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 SRPM libreswan-4.12-3.el9_4.2.src.rpm SHA-256: 1d2b9028bb4c8790c7df3947ddb5ca512028cd84785dad39126aeb72d9a4a887 aarch64 libreswan-4.12-3.el9_4.2.aarch64.rpm SHA-256: 45aa7cfa698d9c2315341a4d8465a33202973e83f24a7400c0fcadec9091b0a6 libreswan-debuginfo-4.12-3.el9_4.2.aarch64.rpm SHA-256: 919d54f02d0745c2cdddbb870249b4ed0013725a563e4a7d77623cecaf7966ad libreswan-debugsource-4.12-3.el9_4.2.aarch64.rpm SHA-256: b675c90b3448291e34a14559537971a5c4c05a190a61185fa9402562bd82485b Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 SRPM libreswan-4.12-3.el9_4.2.src.rpm SHA-256: 1d2b9028bb4c8790c7df3947ddb5ca512028cd84785dad39126aeb72d9a4a887 ppc64le libreswan-4.12-3.el9_4.2.ppc64le.rpm SHA-256: 04e75c7abe958fcb33447d43e53153b55d58f1215e8753ea4678de18251cf2fd libreswan-debuginfo-4.12-3.el9_4.2.ppc64le.rpm SHA-256: 548c1db56aab5fea262b6f55340c220432e81e49aa926a8b0b0fb811e63a4bc6 libreswan-debugsource-4.12-3.el9_4.2.ppc64le.rpm SHA-256: 998ffced630ec3e19f700e421764e3741752a61adff805819b3cc24c341fb8c6 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 SRPM libreswan-4.12-3.el9_4.2.src.rpm SHA-256: 1d2b9028bb4c8790c7df3947ddb5ca512028cd84785dad39126aeb72d9a4a887 s390x libreswan-4.12-3.el9_4.2.s390x.rpm SHA-256: f4466266611ab7ff05cfc9e4203ea8871859db1d324af3ec806cdd33be0b173e libreswan-debuginfo-4.12-3.el9_4.2.s390x.rpm SHA-256: 582ade82ab7e43c98aece120ac894475d0c7a59fcad4c60c91c5b410a676c594 libreswan-debugsource-4.12-3.el9_4.2.s390x.rpm SHA-256: 7063ad3d09d58c9c05a00897dc748c39bdd0746b1c540158fff7a150c7576d0e The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .