Multiple security vulnerabilities have been identified in strongSwan, an IKE/IPsec suite. Affected version range is 6.0.1-6+deb13u7 and earlier. These vulnerabilities can result in crashes, denial of service, or potential remote code execution.
CVE-2026-78123: An undefined memory access vulnerability in the openssl plugin when handling PKCS#7 containers, that can result in a crash.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in strongSwan, an IKE/IPsec suite. Affected version range is 6.0.1-6+deb13u7 and earlier. These vulnerabilities can result in crashes, denial of service, or potential remote code execution.
CVE-2026-78123: An undefined memory access vulnerability in the openssl plugin when handling PKCS#7 containers, that can result in a crash.[emaillocker id="1283"]
CVE-2026-78124: A memory leak in the openssl plugin during the enumeration of certificates in PKCS#7 containers.
CVE-2026-78126: A NULL-pointer dereference vulnerability in the eap-aka plugin when processing an unexpected AKA-Synchronization-Failure message, that can result in a crash.
CVE-2026-78127: Memory leak in libcharon message stringification during the logging of IKE messages, that can result in a denial of service via memory exhaustion.
CVE-2026-78129: An unbounded iteration in libstrongswan when decrypting encrypted PKCS#7 containers, that can result in a denial of service.
CVE-2026-78130: A NULL-Pointer dereference vulnerability in the x509 plugin during the verification of X.509 attribute certificates, that can lead to a denial of service.
CVE-2026-78131: A memory leak in the x509 plugin during the parsing of identities in X.509 attribute certificates, that can lead to a denial of service.
CVE-2026-78132: An infinite loop vulnerability in the x509 plugin when parsing the ietfAttrSyntax ASN.1 type in X.509 attribute certificates, that can lead to a denial of service.
CVE-2026-78133: A vulnerability in libcharon when handling IKEv2 rekeying collisions, that can result in a use-after-free and potentially remote code execution.
CVE-2026-78134: A vulnerability in the eap-peap and eap-ttls plugins in the propagation of authentication details from inner EAP methods. Missing Inner EAP authentication details can result in incorrect identity binding and potential authorization bypass.
CVE-2026-78135: A vulnerability in libcharon when handling CREATE_CHILD_SA requests on unestablished IKE SAs strongSwan, that can result in the creation of a usable Child SA before authentication completes.
These vulnerabilities collectively present significant risks to systems running affected versions of strongSwan.
We recommend you to update strongswan to version 6.0.1-6+deb13u7.
The following reports contain further technical details:
[/emaillocker]