Memory leak in strongSwan - CVE-2026-78124

 

Memory leak in strongSwan - CVE-2026-78124

Published: September 22, 2026


Vulnerability identifier: #VU151581
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78124
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause memory leaks.

The vulnerability exists due to missing cleanup in the openssl plugin's PKCS#7 implementation when enumerating certificates in PKCS#7/CMS containers. A remote attacker can send a PKCS#7 container containing one or more certificates to cause memory leaks.

Exploitation is possible before authentication through IKEv1 certificate payloads and requires at least two messages.


Affected software

strongSwan
Debian Linux
strongswan (Debian package)

How to mitigate CVE-2026-78124

Install security update from vendor's website.

strongSwan - update to 6.1.0
strongswan (Debian package) - update to 6.0.1-6+deb13u7

External References

Related Security Bulletins