rpm package
opensuse/strongswan&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/strongswan&distro=openSUSE%20Tumbleweed
Vulnerabilities (35)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-78135 | Med | 5.6 | < 6.1.0-1.1 | 6.1.0-1.1 | Sep 11, 2026 | libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass. | |
| CVE-2026-78134 | Hig | 7.1 | < 6.1.0-1.1 | 6.1.0-1.1 | Sep 11, 2026 | strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity. | |
| CVE-2026-78133 | Hig | 7.5 | < 6.1.0-1.1 | 6.1.0-1.1 | Sep 11, 2026 | libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling. | |
| CVE-2026-78131 | Low | 3.7 | < 6.1.0-1.1 | 6.1.0-1.1 | Sep 11, 2026 | strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser. | |
| CVE-2026-78130 | Hig | 7.5 | < 6.1.0-1.1 | 6.1.0-1.1 | Sep 11, 2026 | strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser. | |
| CVE-2026-78127 | Low | 3.7 | < 6.1.0-1.1 | 6.1.0-1.1 | Sep 11, 2026 | libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser. | |
| CVE-2026-78126 | Med | 5.9 | < 6.1.0-1.1 | 6.1.0-1.1 | Sep 11, 2026 | strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin. | |
| CVE-2026-78124 | Low | 3.7 | < 6.1.0-1.1 | 6.1.0-1.1 | Sep 11, 2026 | strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime. | |
| CVE-2026-78123 | Med | 5.9 | < 6.1.0-1.1 | 6.1.0-1.1 | Sep 11, 2026 | strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin. | |
| CVE-2026-47895 | Hig | 7.5 | < 6.0.7-1.1 | 6.0.7-1.1 | Aug 22, 2026 | In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed. | |
| CVE-2026-25075 | Hig | 7.5 | < 6.0.5-1.1 | 6.0.5-1.1 | Mar 23, 2026 | strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers c | |
| CVE-2025-9615 | Low | 3.3 | < 6.0.4-1.1 | 6.0.4-1.1 | Jan 26, 2026 | A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from th | |
| CVE-2025-62291 | Hig | 8.1 | < 6.0.3-1.1 | 6.0.3-1.1 | Jan 16, 2026 | In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow. | |
| CVE-2023-26463 | Cri | 9.8 | < 5.9.10-1.1 | 5.9.10-1.1 | Apr 15, 2023 | strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is s | |
| CVE-2021-45079 | Cri | 9.1 | < 5.9.5-1.1 | 5.9.5-1.1 | Jan 31, 2022 | In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication. | |
| CVE-2021-41991 | Hig | 7.5 | < 5.9.4-1.1 | 5.9.4-1.1 | Oct 18, 2021 | The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by mea | |
| CVE-2021-41990 | Hig | 7.5 | < 5.9.4-1.1 | 5.9.4-1.1 | Oct 18, 2021 | The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. | |
| CVE-2018-17540 | Hig | 7.5 | < 5.9.0-1.9 | 5.9.0-1.9 | Oct 3, 2018 | The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate. | |
| CVE-2018-10811 | Hig | 7.5 | < 5.9.0-1.9 | 5.9.0-1.9 | Jun 19, 2018 | strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable. | |
| CVE-2018-5388 | Med | 6.5 | < 5.9.0-1.9 | 5.9.0-1.9 | May 31, 2018 | In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket. |
- affected < 6.1.0-1.1fixed 6.1.0-1.1
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
- affected < 6.1.0-1.1fixed 6.1.0-1.1
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
- affected < 6.1.0-1.1fixed 6.1.0-1.1
libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.
- affected < 6.1.0-1.1fixed 6.1.0-1.1
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
- affected < 6.1.0-1.1fixed 6.1.0-1.1
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
- affected < 6.1.0-1.1fixed 6.1.0-1.1
libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
- affected < 6.1.0-1.1fixed 6.1.0-1.1
strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
- affected < 6.1.0-1.1fixed 6.1.0-1.1
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
- affected < 6.1.0-1.1fixed 6.1.0-1.1
strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
- affected < 6.0.7-1.1fixed 6.0.7-1.1
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
- affected < 6.0.5-1.1fixed 6.0.5-1.1
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers c
- affected < 6.0.4-1.1fixed 6.0.4-1.1
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from th
- affected < 6.0.3-1.1fixed 6.0.3-1.1
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
- affected < 5.9.10-1.1fixed 5.9.10-1.1
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is s
- affected < 5.9.5-1.1fixed 5.9.5-1.1
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
- affected < 5.9.4-1.1fixed 5.9.4-1.1
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by mea
- affected < 5.9.4-1.1fixed 5.9.4-1.1
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
- affected < 5.9.0-1.9fixed 5.9.0-1.9
The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.
- affected < 5.9.0-1.9fixed 5.9.0-1.9
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
- affected < 5.9.0-1.9fixed 5.9.0-1.9
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
Page 1 of 2