Memory leak in strongSwan - CVE-2026-78124
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory leaks.
The vulnerability exists due to missing cleanup in the openssl plugin's PKCS#7 implementation when enumerating certificates in PKCS#7/CMS containers. A remote attacker can send a PKCS#7 container containing one or more certificates to cause memory leaks.
Exploitation is possible before authentication through IKEv1 certificate payloads and requires at least two messages.
Affected software
Debian Linux
strongswan (Debian package)
How to mitigate CVE-2026-78124
strongswan (Debian package) - update to 6.0.1-6+deb13u7