DSA-6487-1 strongswan - security update
Multiple vulnerabilities were found in strongSwan, an IKE/IPsec suite. CVE-2026-78123 An undefined memory access vulnerability in the openssl plugin when handling PKCS#7 containers, that can result in a crash. CVE-2026-78124 A memory leak in the openssl plugin during the enumeration of certificates in PKCS#7 containers. CVE-2026-78126 A NULL-pointer dereference vulnerability in the eap-aka plugin when processing an unexpected AKA-Synchronization-Failure message, that can result in a crash. CVE-2026-78127 Memory leak in libcharon message stringification during the logging of IKE messages, that can result in a denial of service via memory exhaustion. CVE-2026-78129 An unbounded iteration in libstrongswan when decrypting encrypted PKCS#7 containers, that can result in a denial of service. CVE-2026-78130 A NULL-Pointer dereference vulnerability in the x509 plugin during the verification of X.509 attribute certificates, that can lead to a denial of service. CVE-2026-78131 A memory leak in the x509 plugin during the parsing of identities in X.509 attribute certificates, that can lead to a denial of service. CVE-2026-78132 An infinite loop vulnerability in the x509 plugin when parsing the ietfAttrSyntax ASN.1 type in X.509 attribute certificates, that can lead to a denial of service. CVE-2026-78133 A vulnerability in libcharon when handling IKEv2 rekeying collisions, that can result in a use-after-free and potentially remote code execution. CVE-2026-78134 A vulnerability in the eap-peap and eap-ttls plugins in the propagation of authentication details from inner EAP methods. Missing Inner EAP authentication details can result in incorrect identity binding and potential authorization bypass. CVE-2026-78135 A vulnerability in libcharon when handling CREATE_CHILD_SA requests on unestablished IKE SAs strongSwan, that can result in the creation of a usable Child SA before authentication completes. https://security-tracker.debian.org/tracker/DSA-6487-1
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00398.html
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-78123 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78124 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78126 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78127 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78129 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78130 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78131 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78132 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78133 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78134 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78135 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] strongSwan: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans strongSwan (08 septembre 2026)cert-fr-avis
More from Debian Security Advisories
- unknownDSA-6491-1 slurm-wlm - security update2026-09-09
- unknownDSA-6489-1 gst-plugins-base1.0 - security update2026-09-08
- unknownDSA-6490-1 fort-validator - security update2026-09-08
- unknownDSA-6488-1 jbig2dec - security update2026-09-07
- unknownDSA-6486-1 libde265 - security update2026-09-06