PT-2026-27175 · Strongswan+2 · Strongswan+2
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
strongSwan versions 4.5.0 through 6.0.4
Description
An integer underflow flaw exists in the EAP-TTLS AVP parser within strongSwan. This issue allows remote attackers to cause a denial of service by sending specially crafted AVP data with invalid length fields during IKEv2 authentication. The failure to validate AVP length fields before subtraction can lead to excessive memory allocation or a NULL pointer dereference, ultimately crashing the charon IKE daemon.
Recommendations
Update strongSwan to version 6.0.5 or later.
Exploit
Correção
DoS
Integer Underflow
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linuxmint
Ubuntu
Strongswan