Description
strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via infinite loop in PKCS#5 decryption
Action: Assess Impact
AI Analysis

Impact

The vulnerability is an infinite loop triggered during PKCS#5 decryption in strongSwan versions 4.6.2 through 6.0.7, leading to a denial of service by consuming processing resources until the system becomes unresponsive. This weakness represents a classic improper loop control flaw (CWE‑835).

Affected Systems

StrongSwan, as released by the strongSwan project, is affected for versions 4.6.2 through 6.0.7. No other vendors or products are listed in the impact data.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description it is inferred that the attack vector is remote, leveraging network traffic that is processed by the PKCS#5 decryption routine during IPsec negotiations. An attacker who can supply malformed encrypted payloads could potentially trigger the infinite loop, exhausting CPU resources and causing service disruption.

Generated by OpenCVE AI on September 11, 2026 at 03:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to strongSwan 6.1.0 or later, as released on 2026-09-07.
  • If an upgrade cannot be performed immediately, temporarily disable or avoid using the PKCS#5 decryption functionality until the fix is applied.
  • Monitor CPU usage, system logs, and network traffic for signs of denial of service or resource exhaustion.

Generated by OpenCVE AI on September 11, 2026 at 03:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6487-1 strongswan security update
Ubuntu USN Ubuntu USN USN-8789-1 strongSwan vulnerabilities
History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Infinite Loop in PKCS#5 Decryption of strongSwan

Fri, 11 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
First Time appeared Strongswan
Strongswan strongswan
Weaknesses CWE-835
CPEs cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
Vendors & Products Strongswan
Strongswan strongswan
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T14:16:41.560Z

Reserved: 2026-08-22T23:30:57.401Z

Link: CVE-2026-78129

cve-icon Vulnrichment

Updated: 2026-09-11T14:16:38.502Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T02:18:34.207

Modified: 2026-09-14T20:08:56.593

Link: CVE-2026-78129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:30:09Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')