strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade strongswan | Mar 26, 2024 | Dec 7, 2023 |
| Debian | — | Upgrade strongswan | Nov 27, 2023 | Nov 27, 2023 |
| Freebsd | — | Upgrade strongswan | Dec 10, 2025 | Nov 24, 2023 |
| Gentoo Linux | — | Upgrade net-vpn/strongswan. | Jul 9, 2025 | Dec 7, 2023 |
| Suse | — | Upgrade strongswan-ipsecUpgrade strongswan-sqliteUpgrade strongswan-libs0Upgrade strongswan-docUpgrade strongswan-mysqlUpgrade strongswan-hmacUpgrade strongswan-nmUpgrade strongswan | Nov 22, 2023 | Nov 21, 2023 |
| Ubuntu | — | Upgrade strongswanUpgrade strongswan (Ubuntu Pro)Upgrade libstrongswanUpgrade libstrongswan (Ubuntu Pro) | Nov 21, 2023 | Nov 20, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 7, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub