Home / mailings [SECURITY] [DSA 6487-1] strongswan security update
Posted on 07 September 2026
Debian Security Advisory- -------------------------------------------------------------------------
Debian Security Advisory DSA-6487-1 security@debian.org
https://www.debian.org/security/ Yves-Alexis Perez
September 06, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : strongswan
CVE ID : CVE-2026-78123 CVE-2026-78124 CVE-2026-78126 CVE-2026-78127
CVE-2026-78129 CVE-2026-78130 CVE-2026-78131 CVE-2026-78132
CVE-2026-78133 CVE-2026-78134 CVE-2026-78135
Multiple vulnerabilities were found in strongSwan, an IKE/IPsec suite.
CVE-2026-78123
An undefined memory access vulnerability in the openssl plugin when
handling PKCS#7 containers, that can result in a crash.
CVE-2026-78124
A memory leak in the openssl plugin during the enumeration of certificates
in PKCS#7 containers.
CVE-2026-78126
A NULL-pointer dereference vulnerability in the eap-aka plugin when
processing an unexpected AKA-Synchronization-Failure message, that can
result in a crash.
CVE-2026-78127
Memory leak in libcharon message stringification during the logging of IKE
messages, that can result in a denial of service via memory exhaustion.
CVE-2026-78129
An unbounded iteration in libstrongswan when decrypting encrypted PKCS#7
containers, that can result in a denial of service.
CVE-2026-78130
A NULL-Pointer dereference vulnerability in the x509 plugin during the
verification of X.509 attribute certificates, that can lead to a denial of
service.
CVE-2026-78131
A memory leak in the x509 plugin during the parsing of identities in X.509
attribute certificates, that can lead to a denial of service.
CVE-2026-78132
An infinite loop vulnerability in the x509 plugin when parsing the
ietfAttrSyntax ASN.1 type in X.509 attribute certificates, that can lead to
a denial of service.
CVE-2026-78133
A vulnerability in libcharon when handling IKEv2 rekeying collisions, that
can result in a use-after-free and potentially remote code execution.
CVE-2026-78134
A vulnerability in the eap-peap and eap-ttls plugins in the propagation of
authentication details from inner EAP methods. Missing Inner EAP
authentication details can result in incorrect identity binding and
potential authorization bypass.
CVE-2026-78135
A vulnerability in libcharon when handling CREATE_CHILD_SA requests on
unestablished IKE SAs strongSwan, that can result in the creation of a
usable Child SA before authentication completes.
For the stable distribution (trixie), these problems have been fixed in
version 6.0.1-6+deb13u7.
We recommend that you upgrade your strongswan packages.
For the detailed security status of strongswan please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/strongswan
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
