Description
libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
Published: 2026-09-11
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Memory Exhaustion (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from a missing release of memory after its effective lifetime in the IKE message parser of strongSwan. This omission creates a memory leak that can gradually consume system resources, potentially degrading service availability over time. The weakness is a classic case of improper memory management, as identified by CWE-401, and does not permit direct code execution or data tampering. The impact is limited to memory exhaustion, which may manifest as a slowdown or unresponsive VPN service rather than immediate compromise. The CVSS score of 3.7 reflects this low to moderate severity for typical deployments.

Affected Systems

StrongSwan versions from 4.1.2 through 6.0.7 are affected. The vendor, strongSwan, released a fix in version 6.1.0, which addresses the memory handling issue in the IKE parser. Administrators running any of the vulnerable releases should verify their current version and plan an upgrade to the patched release to remove the leak.

Risk and Exploitability

With a CVSS score of 3.7, the vulnerability is considered low to moderate risk. In the absence of an EPSS score or KEV listing, the likelihood of exploitation is uncertain but the condition is purely an exposure to potential denial of service through sustained traffic or attacks that force repeated IKE negotiations. Attackers would need continuous or frequent IKE exchanges to trigger significant memory buildup, implying that the threat is most relevant for long‑running or heavily loaded instances. Nevertheless, the possibility of resource exhaustion makes it a pragmatic concern for stability and reliability.

Generated by OpenCVE AI on September 11, 2026 at 03:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade strongSwan to version 6.1.0 or later
  • Restart the strongSwan service to clear existing memory usage
  • Continuously monitor memory consumption and IKE negotiation rates for abnormal patterns

Generated by OpenCVE AI on September 11, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6487-1 strongswan security update
Ubuntu USN Ubuntu USN USN-8789-1 strongSwan vulnerabilities
History

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Memory Leak in StrongSwan's IKE Message Parser

Fri, 11 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
First Time appeared Strongswan
Strongswan strongswan
Weaknesses CWE-401
CPEs cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
Vendors & Products Strongswan
Strongswan strongswan
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T17:22:42.244Z

Reserved: 2026-08-22T23:29:27.183Z

Link: CVE-2026-78127

cve-icon Vulnrichment

Updated: 2026-09-11T17:22:36.467Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T02:18:34.063

Modified: 2026-09-14T20:09:10.940

Link: CVE-2026-78127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:30:05Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime