Impact
strongSwan 5.0.2 through 6.0.7 processes PKCS#7 data in the OpenSSL plugin without proper memory management, leading to an expired pointer dereference that can corrupt memory. The vulnerability is classified as CWE-825 and can potentially result in program destabilization.
Affected Systems
The affected product is strongSwan, in all supported major releases from 5.0.2 up to and including 6.0.7. No operating‑system restriction is indicated, so the issue applies to installations of these major releases regardless of the underlying OS.
Risk and Exploitability
The CVSS score of 5.9 marks the flaw as moderate. No EPSS score is available and the vulnerability is not listed in CISA KEV, indicating limited or no known exploitation. The likely attack vector is an attacker supplying malicious PKCS#7 data to trigger the parsing routine, which is inferred from the description of how the flaw occurs.
OpenCVE Enrichment
Debian DSA
Ubuntu USN