Use-after-free in strongSwan - CVE-2026-78133
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in libcharon's IKEv2 rekeying collision handling when processing IKE or Child SA rekeying collisions involving multiple key exchanges. A remote user can delay or withhold a CREATE_CHILD_SA response and provide missing or invalid KE payloads to execute arbitrary code.
Successful exploitation requires correctly controlling two indirections.
Affected software
Debian Linux
strongswan (Debian package)
How to mitigate CVE-2026-78133
strongswan (Debian package) - update to 6.0.1-6+deb13u7