Impact
The vulnerability arises from a missing release of memory after its effective lifetime in the IKE message parser of strongSwan. This omission creates a memory leak that can gradually consume system resources, potentially degrading service availability over time. The weakness is a classic case of improper memory management, as identified by CWE-401, and does not permit direct code execution or data tampering. The impact is limited to memory exhaustion, which may manifest as a slowdown or unresponsive VPN service rather than immediate compromise. The CVSS score of 3.7 reflects this low to moderate severity for typical deployments.
Affected Systems
StrongSwan versions from 4.1.2 through 6.0.7 are affected. The vendor, strongSwan, released a fix in version 6.1.0, which addresses the memory handling issue in the IKE parser. Administrators running any of the vulnerable releases should verify their current version and plan an upgrade to the patched release to remove the leak.
Risk and Exploitability
With a CVSS score of 3.7, the vulnerability is considered low to moderate risk. In the absence of an EPSS score or KEV listing, the likelihood of exploitation is uncertain but the condition is purely an exposure to potential denial of service through sustained traffic or attacks that force repeated IKE negotiations. Attackers would need continuous or frequent IKE exchanges to trigger significant memory buildup, implying that the threat is most relevant for long‑running or heavily loaded instances. Nevertheless, the possibility of resource exhaustion makes it a pragmatic concern for stability and reliability.
OpenCVE Enrichment
Debian DSA
Ubuntu USN