PT-2026-27175 · Strongswan+2 · Strongswan+2

·

CVE-2026-25075

·

Publicado

2026-01-01

·

Atualizado

2026-05-04

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions strongSwan versions 4.5.0 through 6.0.4
Description An integer underflow flaw exists in the EAP-TTLS AVP parser within strongSwan. This issue allows remote attackers to cause a denial of service by sending specially crafted AVP data with invalid length fields during IKEv2 authentication. The failure to validate AVP length fields before subtraction can lead to excessive memory allocation or a NULL pointer dereference, ultimately crashing the charon IKE daemon.
Recommendations Update strongSwan to version 6.0.5 or later.

Exploit

Correção

DoS

Integer Underflow

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25075
MGASA-2026-0072
OPENSUSE-SU-2026:10441-1
OPENSUSE-SU-2026:20547-1
SUSE-SU-2026:0978-1
SUSE-SU-2026:0979-1
SUSE-SU-2026:0980-1
SUSE-SU-2026:0981-1
SUSE-SU-2026:1307-1
SUSE-SU-2026:21203-1
USN-8117-1

Produtos afetados

Linuxmint
Ubuntu
Strongswan