Home / mailingsPDF  

[USN-8789-1] strongSwan vulnerabilities

Posted on 21 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8789-1
September 21, 2026

strongswan vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in strongSwan.

Software Description:
- strongswan: IPsec VPN solution

Details:

It was discovered that strongSwan incorrectly handled PKCS#7 containers
in the openssl plugin. A remote attacker could possibly use this issue
to cause strongSwan to crash, resulting in a denial of service.
(CVE-2026-78123)

It was discovered that strongSwan incorrectly handled memory when
enumerating certificates in PKCS#7 containers in the openssl plugin.
A remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2026-78124)

It was discovered that strongSwan incorrectly handled
AKA-Synchronization-Failure messages in the eap-aka plugin. A remote
attacker could possibly use this issue to cause strongSwan to crash,
resulting in a denial of service. (CVE-2026-78126)

It was discovered that strongSwan incorrectly handled memory when
stringifying IKE messages. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2026-78127)

It was discovered that strongSwan incorrectly handled PKCS#5 decryption.
A remote attacker could possibly use this issue to cause strongSwan to
consume excessive resources, leading to a denial of service.
(CVE-2026-78129)

It was discovered that strongSwan incorrectly handled attribute
certificates in the x509 plugin when the issuer name was missing. A
remote attacker could possibly use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2026-78130)

It was discovered that strongSwan incorrectly handled memory when
parsing attribute certificates in the x509 plugin. A remote attacker
could possibly use this issue to obtain sensitive information.
(CVE-2026-78131)

It was discovered that strongSwan incorrectly handled attribute
certificates containing ietfAttrSyntax values in the x509 plugin. A
remote attacker could possibly use this issue to cause strongSwan to
consume excessive resources, leading to a denial of service.
(CVE-2026-78132)

It was discovered that strongSwan incorrectly handled IKEv2 rekeying
collisions with multi-key exchange. A remote attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-78133)

It was discovered that strongSwan incorrectly validated inner EAP
method authentication details in the eap-ttls and eap-peap plugins.
An authenticated user could possibly use this issue to bypass
authentication. (CVE-2026-78134)

It was discovered that strongSwan incorrectly handled CREATE_CHILD_SA
requests on unestablished IKE_SAs. A remote attacker could possibly
use this issue to bypass authentication. (CVE-2026-78135)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libstrongswan 6.0.4-1ubuntu3.2
strongswan 6.0.4-1ubuntu3.2

Ubuntu 24.04 LTS
libstrongswan 5.9.13-2ubuntu4.24.04.5
strongswan 5.9.13-2ubuntu4.24.04.5

Ubuntu 22.04 LTS
libstrongswan 5.9.5-2ubuntu2.8
strongswan 5.9.5-2ubuntu2.8

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8789-1
CVE-2026-78123, CVE-2026-78124, CVE-2026-78126, CVE-2026-78127,
CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132,
CVE-2026-78133, CVE-2026-78134, CVE-2026-78135

Package Information:
https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.2
https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.5
https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.8

--===============6881606942046856911==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP