Impact
The vulnerability is a memory leak in the x509 plugin's attribute certificate parser of strongSwan versions 4.2.0 through 6.0.7. An allocated memory block is never released after its intended lifetime, causing persistent consumption of system memory. An attacker can repeatedly provide crafted attribute certificates to the parser, steadily exhausting available memory and potentially leading to a crash or severe degradation of service. As a result, this flaw could be leveraged for a denial‑of‑service attack, and the un‑released memory may also contain sensitive information for longer than intended.
Affected Systems
The affected product is strongSwan version 4.2.0 through 6.0.7.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Based on the description, the likely attack vector is remote exploitation via crafted X509 attribute certificates sent over a VPN connection. If an attacker can force the server or client to parse numerous malicious attribute certificates, memory usage will climb until the system becomes unresponsive. The exploitation does not require local privilege escalation or special authentication beyond the ability to send certificates to the vulnerable component, implying a broad potential attack surface.
OpenCVE Enrichment
Debian DSA
Ubuntu USN