Libreswan
IPsec VPN implementation for Linux and BSD supporting IKEv1 and IKEv2
IPsec daemon shipping back-to-back CVE releases, one of them found by an AI audit.
◆Recent moves
- 25d ago
5.3.2 Security Release addresses CVE-2026-14957
Fixes a denial of service where a malformed X.509 certificate triggers an assertion failure and crashes the daemon in FIPS mode, repeatable by an attacker. The disclosure that the finding came from an AI-assisted audit of the project's own codebase is unusual to see stated in a release note.
View source ↗ - 1mo ago
5.3.1 Security Release addresses 3 CVEs
A three-CVE security release, bundled with a compile fix for newer GCC versions. It sets up the pattern the following month's release continues — Libreswan is shipping on security findings rather than a feature calendar.
View source ↗ - 2y ago
IKEv1 cryptosuite defaults tightened; systemd libxz dependency dropped
A release candidate whose note is a raw commit log, but the substance is a deliberate overhaul of IKEv1 defaults: SHA2 and AES-GCM added to ESP proposals, DH19 and DH31 added to IKE defaults, and AEAD rejected when combined with non-NULL integrity. Replacing the libsystemd notify path with an internal library also removes a libxz dependency.
View source ↗ - 2y ago
Compile error fix carried over from 4.13
A two-line maintenance tag fixing a compile error in gntoid() and adjusting a test for padded packets. Nothing user-facing.
View source ↗