#Libreswan
Projects done since 2025:

Rocky 9 on the main rack.
IkeV2 vpn For android13-14 w/ docker.
OpenVPN (Bc strongwan/libreswan sucks)
kf2 server (2instance)+spigot updated 1.17.1+L4D2+7D7D
Cloudflare domain+ddns w/ docker.
Letsencrypt SSL everywhere .
EdgeRouter4 automations/optimizations.
February 21, 2025 at 4:51 AM
CVE-2024-9050: NetworkManager-libreswan IPSec VPN plugin local code execution

https://www.openwall.com/lists/oss-security/2024/10/25/1


Original post
October 25, 2024 at 11:48 AM
RHSA-2026:57741: Important: libreswan security update

huntaegis.com
August 20, 2026 at 10:00 PM
Open vSwitch 3.6.2 (latest stable), 3.5.3, 3.4.5 および 3.3.8 (current LTS) がリリースされました。bug fix に加え、Libreswan による IPsec サポートの改善も行われています。

mail.openvswitch.org/pipermail/ov...
[ovs-announce] Open vSwitch 3.6.2, 3.5.3, 3.4.5 and 3.3.8 are available.
mail.openvswitch.org
February 12, 2026 at 12:09 AM
In our last blog, Mohamed explains how netobserv uses #ebpf to track #IPsec usage (and potential errors) within a #kubernetes cluster. Check it out!
👇
netobserv.io/posts/monito...
Monitoring IPSec encryption and decryption using Network Observability
IPSec provides enriched information to indicate if IPsec encryption or decryption using libreswan was successful or not
netobserv.io
July 15, 2025 at 9:25 PM
🔓Red Hat NetworkManager Flaw Let Attackers Gain Root Access To Linux Systems

#infosec #opensource #linux
Red Hat NetworkManager Flaw Let Attackers Gain Root Access To Linux Systems
A serious security vulnerability has been discovered in Red Hat's NetworkManager-libreswan plugin that could allow local attackers to escalate privileges and gain root access to Linux systems.
buff.ly
October 29, 2024 at 12:00 PM
We tried with strongswan, we had no luck whatsoever, tried with both of the available install methods it has, server/cli wise.

We found libreswan and so far with a little docker compose we got a vpn running extremely fast on android.. on android alone.
February 8, 2025 at 12:42 AM
Open vSwitch 3.3.2 及び 2.17.11 がリリースされました。基本 Bug fixes リリースですが、3.3.2 の方は Libreswan 5 の IPsec と互換性が取れるようになりました。#OVS
mail.openvswitch.org/pipermail/ov...
[ovs-announce] Open vSwitch 3.3.2 and 2.17.11 are available.
mail.openvswitch.org
August 27, 2024 at 10:56 PM
In our last blog, Mohamed explains how netobserv uses #ebpf to track #ipsec usage (and potential errors) within a #kubernetes cluster. Check it out!
👇
https://netobserv.io/posts/monitoring-ipsec-encryption-and-decryption-using-network-observability/
Monitoring IPSec encryption and decryption using Network Observability
IPSec provides enriched information to indicate if IPsec encryption or decryption using libreswan was successful or not
netobserv.io
July 15, 2025 at 11:07 AM
手持ちで稼働中の全 Gentoo で AppArmor 有効化し終えた。
プロファイルがやや物足りないので拡充していきたいけど参考にできる設定例何処かに転がってないかな。xl2tpd とか libreswan とか dhcpd とか。
Ubuntu 入れて設定見ればいいか?
July 8, 2023 at 3:29 AM
Libreswan IPsec with PSK and NAT Traversal

This snippet configures a Libreswan IPsec tunnel using pre-shared keys (PSK) and enables NAT traversal (NAT-T) to allow connectivity when endpoints are behind NAT

https://www.valtersit.com/vault/libreswan-ipsec-with-psk-and-nat-traversal-9bbb20/
August 1, 2026 at 12:21 AM
Security updates have been issued by AlmaLinux (grafana and libreswan), Debian (openjdk-11 and openjdk-17), Fedora (opkssh, perl-Mojolicious, and rpm), Mageia (libyang, memcached, nginx,...

🔗 https://lwn.net/Articles/1085855
July 28, 2026 at 1:23 PM
Security updates for Tuesday
Security updates have been issued by **AlmaLinux** (grafana and libreswan), **Debian** (openjdk-11 and openjdk-17), **Fedora** (opkssh, perl-Mojolicious, and rpm), **Mageia** (libyang, memcached, nginx, packages, and sqlite3), **Oracle** (.NET 8.0, acl, buildah, compat-openssl11, compat-poppler022, dogtag-pki, git-lfs, glibc, go-fdo-client, golang, httpd:2.4, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, kernel, libpq, LibRaw, maven:3.8, mysql8.4, nodejs:22, nodejs:24, openssl, podman, poppler, python3.14, samba, sssd, tomcat, tomcat9, vim, and yggdrasil), **Red Hat** (gstreamer1-plugins-bad-free), **SUSE** (afterburn, alsa, apache-ivy, avahi, aws-nitro-enclaves-cli, chromium, cifs-utils, cockpit, cockpit-machines, cockpit-packages, cockpit- podman, cockpit-repos, cockpit-subscriptions, containerd, curl, docker-compose, freetype2, gawk, glib2, google-cloud-sap-agent, gpg2, gstreamer-plugins-bad, gzip, helm, ignition, ImageMagick, jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base, jackson-annotations, jackson-core, jackson-databind, java-11-openjdk, jline3, joe, jq, kernel, libgcrypt, libknet-devel, libsoup, libxml2, mariadb-connector-c, mcphost, net-tools, nghttp2, opennlp, openssl-1_0_0, PackageKit, pam, patch, pcr-oracle, perl, perl-DBI, perl-HTTP-Date, python-aiohttp, python-cryptography, python-Pillow, python-pyasn1, python-soupsieve, python-tornado, python-tornado6, python-urllib3, python3, radvd, rust-keylime, s390-tools, shibboleth-sp, sssd, systemd, tiff, vim, and wpa_supplicant), and **Ubuntu** (FreeIPMI, glibc, linux-aws, linux-aws, linux-raspi, linux-aws-6.8, linux-aws-fips, linux-azure, linux-azure-6.8, linux-azure, linux-oracle, linux-azure-5.15, linux-azure-fde-5.15, linux-oracle-5.15, linux-azure-6.17, linux-azure-fde, linux-azure-fde-6.17, linux-azure-fde-6.8, linux-azure-fips, linux-hwe-6.8, linux-ibm, linux-ibm-6.8, linux-nvidia-tegra, linux-xilinx, linux-oracle-6.17, roc-toolkit, and samba).
lwn.net
July 28, 2026 at 5:36 PM
RHSA-2026:46396: Important: libreswan security update

huntaegis.com
July 27, 2026 at 3:36 AM
RHSA-2026:46397: Important: libreswan security update

huntaegis.com
July 27, 2026 at 3:55 AM
📌 CVE-2026-50722 - Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IK... https://www.cyberhub.blog/cves/CVE-2026-50722
CVE-2026-50722
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH
www.cyberhub.blog
July 22, 2026 at 6:37 PM
📌 CVE-2026-50721 - Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG pay... https://www.cyberhub.blog/cves/CVE-2026-50721
CVE-2026-50721
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack t
www.cyberhub.blog
July 22, 2026 at 6:07 PM
Security updates for Tuesday
Security updates have been issued by **AlmaLinux** (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), **Debian** (samba), **Fedora** (c-ares, dnsx, freerdp, gpsd, libreswan, libseccomp, libtiff, mingw-python-idna, mingw-python-pip, openssh, python-pillow, wget1, and wireshark), **Mageia** (golang, graphicsmagick, haveged, libssh2, nginx, nilfs-utils, perl-CGI-Session, perl-Imager, perl-JavaScript-Minifier-XS, php, php8.4, php8.5, python-nltk, sqlite3, and xmlstarlet), **Oracle** (.NET 10.0, .NET 9.0, container-tools:ol8, firefox, giflib, glibc, go-fdo-client, go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, hplip, httpd, image-builder, kernel, libtiff, mod_http2, pacemaker, perl-DBI:1.641, perl-HTTP-Daemon, php:8.2, python-markdown, ruby4.0, systemd, and thunderbird), **Red Hat** (buildah, container-tools:rhel8, dracut, golang-github-openprinting-ipp-usb, libtiff, osbuild-composer, python-urllib3, python3.12-urllib3, python3.14-urllib3, and runc), **SUSE** (389-ds, chromedriver, gstreamer-plugins-bad, libreoffice, libsuricata8_0_6, podman, python311, and sssd), and **Ubuntu** (apache2, freerdp3, freetype, libde265, libxfont, linux, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-realtime, linux-realtime-6.8, linux, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-gcp, linux-gke, linux-realtime, linux-gcp-6.17, linux-realtime-6.17, linux-gcp-fips, linux-hwe-7.0, linux-nvidia-tegra-5.15, linux-oem-7.0, nginx, php8.1, php8.3, php8.5, rlottie, sqlite3, and wget).
lwn.net
July 21, 2026 at 8:49 PM
[Backport release-26.05] libreswan: 5.3.1 -> 5.3.2

https://github.com/NixOS/nixpkgs/pull/542945

#security
July 17, 2026 at 4:00 PM
July 17, 2026 at 1:31 PM