Use-after-free in strongSwan - CVE-2026-78133

 

Use-after-free in strongSwan - CVE-2026-78133

Published: September 22, 2026


Vulnerability identifier: #VU151585
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78133
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to use-after-free in libcharon's IKEv2 rekeying collision handling when processing IKE or Child SA rekeying collisions involving multiple key exchanges. A remote user can delay or withhold a CREATE_CHILD_SA response and provide missing or invalid KE payloads to execute arbitrary code.

Successful exploitation requires correctly controlling two indirections.


Affected software

strongSwan
Debian Linux
strongswan (Debian package)

How to mitigate CVE-2026-78133

Install security update from vendor's website.

strongSwan - update to 6.1.0
strongswan (Debian package) - update to 6.0.1-6+deb13u7

External References

Related Security Bulletins