NULL pointer dereference in strongSwan - CVE-2026-78126
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a missing state check in the eap-aka plugin when processing an AKA-Synchronization-Failure message before issuing an AKA-Challenge. A remote attacker can send an unexpected AKA-Synchronization-Failure message to cause a denial of service.
The issue occurs when the request_identity option is enabled, which is the default configuration.
Affected software
Debian Linux
strongswan (Debian package)
How to mitigate CVE-2026-78126
strongswan (Debian package) - update to 6.0.1-6+deb13u7