========================================================================== Ubuntu Security Notice USN-8117-1 March 23, 2026
strongswan vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: strongSwan could be made to consume resources or crash if it received specially crafted network traffic. Software Description: - strongswan: IPsec VPN solution Details: Kazuma Matsumoto discovered that strongSwan incorrectly handled EAP-TTLS AVPs when using the eap-ttls plugin. An attacker could possibly use this issue to cause strongSwan to consume resources and crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libstrongswan 6.0.1-6ubuntu4.2 strongswan 6.0.1-6ubuntu4.2 Ubuntu 24.04 LTS libstrongswan 5.9.13-2ubuntu4.24.04.2 strongswan 5.9.13-2ubuntu4.24.04.2 Ubuntu 22.04 LTS libstrongswan 5.9.5-2ubuntu2.5 strongswan 5.9.5-2ubuntu2.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8117-1 CVE-2026-25075 Package Information: https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.2 https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.2 https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.5
signature.asc
Description: OpenPGP digital signature
