PT-2026-35584 · Canonical+3 · Charon-Cmd+14
CVE-2026-35334
·
Publicado
2026-04-22
·
Atualizado
2026-06-18
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
USN-8196-1 fixed vulnerabilities in strongSwan. This update provides the
corresponding update to Ubuntu 26.04 LTS.
Original advisory details:
Haruto Kimura discovered that strongSwan incorrectly handled the
supported versions extension in TLS. A remote attacker could possibly use
this issue to cause strongSwan to stop responding, resulting in a denial
of service. (CVE-2026-35328)
Haruto Kimura discovered that strongSwan incorrectly handled certain
encrypted PKCS#7 containers. A remote attacker could possibly use this
issue to cause strongSwan to crash, resulting in a denial of service.
(CVE-2026-35329)
Lukas Johannes Moeller discovered that strongSwan incorrectly handled
certain EAP-SIM/AKA attributes. A remote attacker could use this issue to
cause strongSwan to stop responding, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-35330)
Haruto Kimura discovered that strongSwan incorrectly handled processing of
X.509 name constraints. A remote attacker could possibly use this issue to
bypass excluded name constraints. (CVE-2026-35331)
Haruto Kimura discovered that strongSwan incorrectly processed ECDH public
values. A remote attacker could possibly use this issue to cause
strongSwan to crash, resulting in a denial of service. (CVE-2026-35332)
Lukas Johannes Moeller discovered that strongSwan incorrectly handled
certain RADIUS attributes. A remote attacker could possibly use this issue
to cause strongSwan to crash, resulting in a denial of service.
(CVE-2026-35333)
Ryo Shimada discovered that strongSwan incorrectly handled RSA decryption.
A remote attacker could possibly use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2026-35334)
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Charon-Cmd
Charon-Systemd
Libcharon-Extauth-Plugins
Libcharon-Extra-Plugins
Libstrongswan
Libstrongswan-Extra-Plugins
Libstrongswan-Standard-Plugins
Strongswan
Strongswan-Charon
Strongswan-Libcharon
Strongswan-Nm
Strongswan-Pki
Strongswan-Scepclient
Strongswan-Starter
Strongswan-Swanctl