Known vulnerabilities in strongswan-hmac
Vendor:
SUSE
Software:
strongswan-hmac
Software CPE:
cpe:2.3:o:suse:strongswan-hmac:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
16
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
5.9.12-150600.3.23.2
5.9.11-150400.19.40.2
5.1.3-26.43.2
5.9.11-150500.5.28.2
5.9.11-150500.5.23.2
5.9.11-150400.19.35.1
5.1.3-26.38.1
5.9.12-150600.3.16.1
5.1.3-26.35.1
5.1.3-26.32.1
5.9.11-150400.19.26.1
5.9.14-150700.3.9.1
5.9.12-150600.3.11.1
5.9.11-150500.5.14.1
5.9.14-150700.3.6.1
5.9.11-150400.19.23.1
5.9.12-150600.3.8.1
5.1.3-26.29.1
5.9.11-150500.5.9.1
5.8.2-150200.11.45.1
5.9.11-150400.19.20.1
5.9.12-150600.3.5.2
5.9.14-150700.3.3.1
5.9.12-150600.3.2.1
5.9.11-150500.5.6.1
5.9.11-150400.19.17.2
5.8.2-150200.11.42.2
5.8.2-150000.4.23.2
5.8.2-11.24.1
5.8.2-4.17.1
5.8.2-150400.19.3.3
5.1.3-26.23.1
5.8.2-150200.11.30.1
5.8.2-4.14.2
5.1.3-26.16.1
5.8.2-11.21.1
Vulnerabilities (16)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU151590 - Missing release of memory after effective lifetime CVE-2026-78127 |
CWE-401 | Medium | 5.1.3-26.43.2, 5.9.11-150400.19.40.2, 5.9.11-150500.5.28.2, 5.9.12-150600.3.23.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093056 and 4 more |
||
| #VU151589 - Unchecked Input for Loop Condition CVE-2026-78129 |
CWE-606 | Medium | 5.1.3-26.43.2, 5.9.11-150400.19.40.2, 5.9.11-150500.5.28.2, 5.9.12-150600.3.23.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093056 and 4 more |
||
| #VU151588 - NULL Pointer Dereference CVE-2026-78130 |
CWE-476 | Medium | 5.1.3-26.43.2, 5.9.11-150400.19.40.2, 5.9.11-150500.5.28.2, 5.9.12-150600.3.23.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093056 and 4 more |
||
| #VU151587 - Missing release of memory after effective lifetime CVE-2026-78131 |
CWE-401 | Medium | 5.1.3-26.43.2, 5.9.11-150400.19.40.2, 5.9.11-150500.5.28.2, 5.9.12-150600.3.23.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093056 and 4 more |
||
| #VU151586 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2026-78132 |
CWE-835 | Medium | 5.9.11-150400.19.40.2, 5.9.11-150500.5.28.2, 5.9.12-150600.3.23.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093056 and 3 more |
||
| #VU151584 - Authentication Bypass by Spoofing CVE-2026-78134 |
CWE-290 | Low | 5.9.11-150400.19.40.2, 5.9.11-150500.5.28.2, 5.9.12-150600.3.23.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093056 and 3 more |
||
| #VU151583 - Improper Authentication CVE-2026-78135 |
CWE-287 | Medium | 5.9.11-150400.19.40.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093059 and 1 more |
||
| #VU151582 - Use of Uninitialized Variable CVE-2026-78123 |
CWE-457 | Medium | 5.1.3-26.43.2, 5.9.11-150400.19.40.2, 5.9.11-150500.5.28.2, 5.9.12-150600.3.23.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093056 and 4 more |
||
| #VU151581 - Missing release of memory after effective lifetime CVE-2026-78124 |
CWE-401 | Medium | 5.1.3-26.43.2, 5.9.11-150400.19.40.2, 5.9.11-150500.5.28.2, 5.9.12-150600.3.23.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093056 and 4 more |
||
| #VU151580 - NULL Pointer Dereference CVE-2026-78126 |
CWE-476 | Medium | 5.1.3-26.43.2, 5.9.11-150400.19.40.2, 5.9.11-150500.5.28.2, 5.9.12-150600.3.23.2 | 22.09.2026 |
SB2026092230 SB2026092245 SB2026093056 and 4 more |
||
| #VU117683 - Integer underflow CVE-2025-62291 |
CWE-191 | High | 5.1.3-26.29.1, 5.8.2-150200.11.45.1, 5.9.11-150400.19.20.1, 5.9.11-150500.5.9.1, 5.9.12-150600.3.5.2, 5.9.14-150700.3.3.1 | 27.10.2025 |
SB2025102750 SB2025102756 SB2025102759 and 16 more |
||
| #VU83305 - Memory corruption CVE-2023-41913 |
CWE-119 | High | 5.8.2-150000.4.23.2, 5.8.2-150200.11.42.2, 5.9.11-150400.19.17.2, 5.9.11-150500.5.6.1 | 20.11.2023 |
SB2023112058 SB2023112065 SB2023112102 and 14 more |
||
| #VU67813 - Improper Certificate Validation CVE-2022-40617 |
CWE-295 | Medium | 5.1.3-26.23.1, 5.8.2-150200.11.30.1, 5.8.2-150400.19.3.3 | 03.10.2022 |
SB2022100335 SB2022100336 SB2022100345 and 10 more |
||
| #VU59994 - State Issues CVE-2021-45079 |
CWE-371 | High | 5.8.2-4.17.1, 5.8.2-11.24.1 | 25.01.2022 |
SB2022012520 SB2022012529 SB2022012445 and 12 more |
||
| #VU57554 - Integer overflow CVE-2021-41990 |
CWE-190 | High | 5.8.2-4.14.2, 5.8.2-11.21.1 | 19.10.2021 |
SB2021101946 SB2021101947 SB2022020403 and 10 more |
||
| #VU57553 - Integer overflow CVE-2021-41991 |
CWE-190 | High | 5.1.3-26.16.1, 5.8.2-4.14.2, 5.8.2-11.21.1 | 19.10.2021 |
SB2021101946 SB2021101947 SB2021101950 and 13 more |