Description
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
Published: 2026-09-11
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Resource Exhaustion
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a memory leak in the x509 plugin's attribute certificate parser of strongSwan versions 4.2.0 through 6.0.7. An allocated memory block is never released after its intended lifetime, causing persistent consumption of system memory. An attacker can repeatedly provide crafted attribute certificates to the parser, steadily exhausting available memory and potentially leading to a crash or severe degradation of service. As a result, this flaw could be leveraged for a denial‑of‑service attack, and the un‑released memory may also contain sensitive information for longer than intended.

Affected Systems

The affected product is strongSwan version 4.2.0 through 6.0.7.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Based on the description, the likely attack vector is remote exploitation via crafted X509 attribute certificates sent over a VPN connection. If an attacker can force the server or client to parse numerous malicious attribute certificates, memory usage will climb until the system becomes unresponsive. The exploitation does not require local privilege escalation or special authentication beyond the ability to send certificates to the vulnerable component, implying a broad potential attack surface.

Generated by OpenCVE AI on September 11, 2026 at 04:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update strongSwan to version 6.1.0 or later, which fixes the memory release issue in the x509 plugin.
  • Restart any strongSwan services after the upgrade to ensure the new code is loaded.
  • After updating, monitor system memory usage to verify that the leak has been resolved and that no suspicious memory growth occurs.

Generated by OpenCVE AI on September 11, 2026 at 04:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6487-1 strongswan security update
Ubuntu USN Ubuntu USN USN-8789-1 strongSwan vulnerabilities
History

Fri, 11 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Memory Leak in strongSwan X509 Attribute Certificate Parser

Fri, 11 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
First Time appeared Strongswan
Strongswan strongswan
Weaknesses CWE-401
CPEs cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
Vendors & Products Strongswan
Strongswan strongswan
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T20:04:15.477Z

Reserved: 2026-08-22T23:34:10.554Z

Link: CVE-2026-78131

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T02:18:34.490

Modified: 2026-09-14T20:08:24.203

Link: CVE-2026-78131

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:30:05Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime