In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade strongswan | Aug 24, 2026 | Aug 22, 2026 |
| Debian | — | Upgrade strongswan | Jun 9, 2026 | Jun 9, 2026 |
| Freebsd | — | Upgrade strongswan | Jun 15, 2026 | Jun 8, 2026 |
| Ubuntu | — | Upgrade strongswanUpgrade libstrongswan | Jun 9, 2026 | Jun 8, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub