Description
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
Published: 2026-08-22
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A double‑free memory error occurs when strongSwan parses or clones an EAP‑Identity that is syntactically empty but not NULL encoded. The bug causes duplicate identity objects to be freed twice when the duplicates are destroyed, which can be leveraged by an attacker to corrupt memory and potentially execute arbitrary code or cause the process to crash. The flaw is categorized as CWE‑415, meaning unsafe deallocation of heap memory.

Affected Systems

The vulnerability affects the StrongSwan VPN software, specifically versions earlier than 6.0.7 released by the strongSwan group. Any deployment using a pre‑6.0.7 build is susceptible to the double‑free attack via the EAP authentication pathway.

Risk and Exploitability

The CVSS score of 7.5 classifies this flaw as high severity. Although the EPSS score is not available, the absence of a KEV listing does not mitigate the risk; an adversary who can initiate an EAP authentication session may trigger the vulnerability remotely. The exploit path requires crafting an EAP identity with an empty but non‑NULL encoding, then sending it to the VPN server. Successful exploitation could lead to a denial‑of‑service or, in the worst case, arbitrary code execution on the server.

Generated by OpenCVE AI on August 22, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to strongSwan 6.0.7 or newer, which removes the double‑free bug.
  • If an upgrade is not feasible, disable EAP authentication or tightly restrict remote accounts that can initiate EAP sessions.
  • Monitor authentication logs for repeated EAP errors or unusual traffic patterns that could indicate an attacker attempting the double‑free trigger.

Generated by OpenCVE AI on August 22, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6330-1 strongswan security update
Ubuntu USN Ubuntu USN USN-8407-1 strongSwan vulnerability
History

Sat, 22 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Double‑Free Vulnerability in Identity Parsing of StrongSwan EAP-Identity

Sat, 22 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
First Time appeared Strongswan
Strongswan strongswan
Weaknesses CWE-415
CPEs cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
Vendors & Products Strongswan
Strongswan strongswan
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-22T22:01:26.298Z

Reserved: 2026-05-20T00:00:00.000Z

Link: CVE-2026-47895

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T22:16:28.153

Modified: 2026-08-22T22:16:28.153

Link: CVE-2026-47895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-23T00:30:17Z

Weaknesses