CVE-2026-12413

QRadar SIEM: Off-by-one Error (CVE-2026-12413)

Affected

  • IBM/QRadar SIEM range_unparsed *..<7.5.0 UP15 IF06

Description

A flaw was found in Libreswan's IKEv2 fragment reassembly mechanism. When a VPN gateway processes incoming split network packets (fragments) containing unexpected data, an off-by-one boundary validation error triggers an internal program safety check (assertion failure). A remote, unauthenticated attacker can exploit this by sending a specific sequence of malformed IKEv2 fragments to an exposed gateway, causing the Libreswan daemon to immediately crash and restart. While this flaw does not allow data theft or unauthorized system access, a continuous stream of these packets will lead to a persistent Denial of Service (DoS) for legitimate VPN users.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

IBMQRadar SIEM
<7.5.0 UP15 IF06

Metrics

7.5
Source: nvd-v3
47.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
high
no public PoC known
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-02 21:19 UTC
CWE-193, CWE-617

Weakness classes (CWE)

  • CWE-193Base

    Off-by-one Error

    A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

    cwe.mitre.org →
  • CWE-617Base

    Reachable Assertion

    The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-07-02 22:16 UTC· d42dc95b-23f1-4e06-9076-20753a0fb0df
    • Affected: libreswan
    • Description: An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • CWE: CWE-193

Linked advisories