- What: Debian releases a security update for strongswan
- Impact: Systems using affected versions may need to apply the update
[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6330-1] strongswan security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6330-1] strongswan security update From: Yves-Alexis Perez <corsac@debian.org> Date: Mon, 08 Jun 2026 15:30:51 +0200 Message-id: <[🔎] 6a26c40b.1a000a.90427e9@scapa.corsac.net> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6330-1 security@debian.org https://www.debian.org/security/ Yves-Alexis Perez June 08, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : strongswan CVE ID : CVE-2026-47895 Debian Bug : Elliott Childre identified a vulnerability in strongSwan, an IKE/IPsec suite. The bug happens when cloning certain identities and can lead to a double-free, a daemon crash (leading to denial of service) and potentially remote code execution. Upstream lists several mitigations: - - Servers that don't use EAP or XAuth authentication are not vulnerable to remote attacks. - - Servers that use EAP authentication but delegate it to a RADIUS server and don't request an EAP-Identity themselves are not vulnerable either. However, note that the `eap-radius` plugin parses `Class` and `Filter-Id` attributes as group identities if enabled, in which case a rogue RADIUS server is able to trigger the issue. - - Servers that use IKEv1 with XAuth are not vulnerable unless they use the `xauth-eap` plugin. For the oldstable distribution (bookworm), this problem has been fixed in version 5.9.8-5+deb12u5. For the stable distribution (trixie), this problem has been fixed in version 6.0.1-6+deb13u6. We recommend that you upgrade your strongswan packages. For the detailed security status of strongswan please refer to its security tracker page at: https://security-tracker.debian.org/tracker/strongswan Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAmomw7QACgkQ3rYcyPpX RFt6Twf9FmaTj+peT37ySfwbw+bv5I595zfhUk4skx6UjhmfTdoxiPTj4KOh4Yqr M9RgDcujDx7R68sjVmKwhCpBBv17PW4TDF5wyt8VYZrGON5lRvv9OuP2TN7Hxh0h CAPvKp/H8bNJhyrgEFTYb8sb5eH/SitKAckwoJFasL41vZ5WAaVVoK4FuepjIkMc k8yDR6VdEDki8Ob/0UUt8KW0GtiFMphB0Jfyq+vKZZ43+Syo3WyBw+wJ249J6NMc /l2abOC7M9PTWJnJllhOI8YRUKlOc9X5pIEGDcLdpBfI+66oU1rU75y5OyHaDb+I YIMto1HBI95CbRk4dNgp/BQLzFy0BQ== =ICRa -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Yves-Alexis Perez (on-list) Yves-Alexis Perez (off-list) Prev by Date: [SECURITY] [DSA 6335-1] openssl security update Previous by thread: [SECURITY] [DSA 6335-1] openssl security update Index(es): Date Thread