Impact
strongSwan versions 5.0.2 through 6.0.7 contain a flaw in the OpenSSL plugin that permits PKCS#7 certificate enumeration. The routine fails to release memory after the objects’ effective lifetime, creating a memory leak (CWE‑401). Although each individual leak may be small, repeated use over time can exhaust system memory and cause a denial‑of‑service condition for the strongSwan process.
Affected Systems
The vulnerability affects the strongSwan vendor’s open‑source VPN software, specifically all releases between 5.0.2 and 6.0.7 inclusive. Clients running these versions on any platform that uses the OpenSSL plugin are at risk.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and no EPSS value is available, so the likelihood of exploitation is unknown. This vulnerability is not listed in CISA’s KE vector could be remote if an adversary can force the strongSwan server to enumerate certificates, but the precise vector is not explicitly stated in the advisory; it is inferred that remote access to the OpenSSL plugin is required.
OpenCVE Enrichment
Debian DSA
Ubuntu USN