-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6487-1                   [email protected]
https://www.debian.org/security/                        Yves-Alexis Perez
September 06, 2026                    https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : strongswan
CVE ID         : CVE-2026-78123 CVE-2026-78124 CVE-2026-78126 CVE-2026-78127 
                 CVE-2026-78129 CVE-2026-78130 CVE-2026-78131 CVE-2026-78132 
                 CVE-2026-78133 CVE-2026-78134 CVE-2026-78135

Multiple vulnerabilities were found in strongSwan, an IKE/IPsec suite.

CVE-2026-78123

    An undefined memory access vulnerability in the openssl plugin when
    handling PKCS#7 containers, that can result in a crash.

CVE-2026-78124

    A memory leak in the openssl plugin during the enumeration of certificates
    in PKCS#7 containers.

CVE-2026-78126

    A NULL-pointer dereference vulnerability in the eap-aka plugin when
    processing an unexpected AKA-Synchronization-Failure message, that can
    result in a crash.

CVE-2026-78127

    Memory leak in libcharon message stringification during the logging of IKE
    messages, that can result in a denial of service via memory exhaustion.

CVE-2026-78129

    An unbounded iteration in libstrongswan when decrypting encrypted PKCS#7
    containers, that can result in a denial of service.

CVE-2026-78130

    A NULL-Pointer dereference vulnerability in the x509 plugin during the
    verification of X.509 attribute certificates, that can lead to a denial of
    service.

CVE-2026-78131

    A memory leak in the x509 plugin during the parsing of identities in X.509
    attribute certificates, that can lead to a denial of service.

CVE-2026-78132

    An infinite loop vulnerability in the x509 plugin when parsing the
    ietfAttrSyntax ASN.1 type in X.509 attribute certificates, that can lead to
    a denial of service.

CVE-2026-78133

    A vulnerability in libcharon when handling IKEv2 rekeying collisions, that
    can result in a use-after-free and potentially remote code execution.

CVE-2026-78134

    A vulnerability in the eap-peap and eap-ttls plugins in the propagation of
    authentication details from inner EAP methods. Missing Inner EAP
    authentication details can result in incorrect identity binding and
    potential authorization bypass.

CVE-2026-78135

    A vulnerability in libcharon when handling CREATE_CHILD_SA requests on
    unestablished IKE SAs strongSwan, that can result in the creation of a
    usable Child SA before authentication completes.

For the stable distribution (trixie), these problems have been fixed in
version 6.0.1-6+deb13u7.

We recommend that you upgrade your strongswan packages.

For the detailed security status of strongswan please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/strongswan

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAmqe5MYACgkQ3rYcyPpX
RFsinQf/ZSKPCwfn1Z0OwM8FfBMq/EMavYdwcUtbYIgn9b5zqCLLtoYOn3jad5Uv
1H2iVwofXl5FcCFbgjVI7/9nsiXSVXWmGfIm65KSADzx2YNjPZ874T+W86hVHaJY
6IBpdpkRNDFMAEid9d5770qlbfYHlmGJhE89cY30h4XpiSoVfXvAw/4JpbmmZxts
SwwN+/hQdT5K1dToWrWtyOYM1FvauQttseEKwYAsJe0lGD2Tcn9S12eHoROUm/jH
U7gtO96YTMpzkRQxskLFirgj6D5RPdYL+5v0YRHwr9dtxgjFahEEyprr7iwIU8aD
xykcETniiHBNJjo0u6ckw86Mbxhhag==
=hFC2
-----END PGP SIGNATURE-----

Reply via email to