NULL pointer dereference in strongSwan - CVE-2026-78130
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the x509 plugin's attribute certificate validation when validating an X.509 attribute certificate without an issuerName field or AuthorityKeyIdentifier extension. A remote attacker can submit a specially crafted attribute certificate to cause a crash.
Exploitation requires the x509 and acert plugins to be loaded.
Affected software
Debian Linux
strongswan (Debian package)
How to mitigate CVE-2026-78130
strongswan (Debian package) - update to 6.0.1-6+deb13u7