The strongSwan project reports:
strongSwan 6.1.0 fixes eleven vulnerabilities:
- CVE-2026-78123: A flaw in the openssl plugin in the
processing of PKCS#7 containers can result in a crash.
Affects 5.0.2 and newer.
- CVE-2026-78124: A flaw in the openssl plugin in the
enumeration of certificates in PKCS#7 containers can result
in memory leaks. Affects 5.0.2 and newer.
- CVE-2026-78126: A flaw in the eap-aka plugin in the
processing of an unexpected AKA-Synchronization-Failure can
result in a crash. Affects 4.1.10 and newer.
- CVE-2026-78127: A flaw in libcharon in the logging of IKE
messages can result in a denial of service via memory
exhaustion. Affects 4.1.2 and newer.
- CVE-2026-78129: A flaw in libstrongswan in the processing
of encrypted PKCS#7 containers can result in a denial of
service. Affects 4.6.2 and newer.
- CVE-2026-78130: A flaw in the x509 plugin in the
verification of X.509 attribute certificates can lead to a
denial of service. Affects 4.2.0 and newer.
- CVE-2026-78131: A flaw in the x509 plugin in the parsing
of identities in X.509 attribute certificates can lead to a
denial of service via memory exhaustion. Affects 4.2.0 and
newer.
- CVE-2026-78132: A flaw in the x509 plugin in the parsing
of the ietfAttrSyntax ASN.1 type in X.509 attribute
certificates can lead to a denial of service. Affects 5.1.3
and newer.
- CVE-2026-78133: A flaw in libcharon in the handling of
IKEv2 rekeying collisions can result in a use-after-free and
potentially remote code execution. Affects 6.0.0 and
newer.
- CVE-2026-78134: A flaw in the eap-peap and eap-ttls
plugins in the propagation of authentication details from
inner EAP methods can result in incorrect identity binding
and potential authorization bypass. Affects 4.5.0 and
newer.
- CVE-2026-78135: A flaw in libcharon in the handling of
CREATE_CHILD_SA requests on unestablished IKE SAs can result
in the creation of a usable Child SA before authentication
completes. Affects 5.9.7 and newer.