Missing release of memory after effective lifetime in Cisco Systems, Inc products - CVE-2026-20012

 

Missing release of memory after effective lifetime in Cisco Systems, Inc products - CVE-2026-20012

Published: March 25, 2026


Vulnerability identifier: #VU124595
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20012
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the IKEv2 packet parser when handling IKEv2 packets. A remote attacker can send specially crafted IKEv2 packets to an affected device to trigger a memory leak, resulting in a denial of service condition.

A successful exploit on Cisco IOS and IOS XE Software may cause the device to reload, while on Cisco Secure Firewall ASA and FTD Software it may partially exhaust system memory, leading to system instability and requiring a manual reboot to recover.


Affected software

Cisco IOS XE
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2026-20012

Install security update from vendor's website.

Cisco IOS XE - update to 17.15.5
Cisco Firewall Threat Defense (FTD) - addressed in versions 7.0.9, 7.2.11, 7.4.3, 7.6.4, 7.7.11
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.85, 9.18.4.71, 9.20.4.10, 9.22.2.13, 9.23.1.19

External References

Related Security Bulletins