Impact
The vulnerability is an infinite loop triggered by the x509 plugin’s attribute certificate parser when processing ietfAttrSyntax certificates. The loop consumes CPU resources and can cause a denial of service by blocking normal operation of the strongSwan process. It maps to the weakness CWE-835, which indicates an unchecked loop or recursion that can lead to resource exhaustion.
Affected Systems
StrongSwan implementations from version 5.1.3 through 6.0.7 are affected. Any deployment of these versions that processes X.509 attribute certificates is vulnerable.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV at this time. The likely attack vector is that an attacker supplies a crafted attribute certificate to a strongSwan instance, causing the infinite loop; it is inferred that this can be remotely triggered through certificate exchange procedures.
OpenCVE Enrichment
Debian DSA
Ubuntu USN