Security update for strongswan
This update for strongswan fixes the following issues - CVE-2026-35328: infinite loop when handling supported versions TLS extension (bsc#1261712). - CVE-2026-35329: null pointer dereference when processing padding in PKCS#7 (bsc#1261717). - CVE-2026-35330: integer underflow when handling EAP-SIM/AKA attributes (bsc#1261705). - CVE-2026-35331: accepting certificates violating name constraints (bsc#1261718). - CVE-2026-35332: null pointer dereference when handling ECDH public value in TLS (bsc#1261708). - CVE-2026-35333: integer underflow when handling RADIUS attributes (bsc#1261706). - CVE-2026-35334: possible null pointer dereference in RSA decryption (bsc#1261720). - CVE-2026-47895: double-free when destroying certain cloned identities (bsc#1266360).
AI Analysis
Technical Summary
This update for strongSwan fixes seven distinct vulnerabilities (CVE-2026-35328 through CVE-2026-35334) and one additional CVE (CVE-2026-47895). The issues include an infinite loop triggered by supported versions TLS extension, null pointer dereferences in PKCS#7 padding processing and ECDH public value handling, integer underflows in EAP-SIM/AKA and RADIUS attribute processing, acceptance of certificates violating name constraints, a possible null pointer dereference during RSA decryption, and a double-free vulnerability when destroying certain cloned identities. These vulnerabilities affect strongSwan version 5.9.11-150500.5.23.2 on the aarch64 platform as distributed by SUSE. No CVSS scores are provided. The vulnerabilities collectively pose a high severity risk.
Potential Impact
The vulnerabilities can cause denial of service conditions such as infinite loops and crashes due to null pointer dereferences and double-free errors. Acceptance of certificates violating name constraints may weaken authentication guarantees. Integer underflows in protocol attribute handling could lead to unexpected behavior or memory corruption. These issues collectively undermine the reliability and security of strongSwan VPN deployments on affected versions.
Mitigation Recommendations
A security update is available from the SUSE Product Security Team that addresses these vulnerabilities in strongSwan version 5.9.11-150500.5.23.2 for aarch64. Users should apply the official SUSE patch or update to the fixed version as provided by SUSE. Patch status is confirmed by the vendor advisory. No cloud service remediation applies as this is not a cloud service. There are no known exploits in the wild at this time.
Security update for strongswan
Description
This update for strongswan fixes the following issues - CVE-2026-35328: infinite loop when handling supported versions TLS extension (bsc#1261712). - CVE-2026-35329: null pointer dereference when processing padding in PKCS#7 (bsc#1261717). - CVE-2026-35330: integer underflow when handling EAP-SIM/AKA attributes (bsc#1261705). - CVE-2026-35331: accepting certificates violating name constraints (bsc#1261718). - CVE-2026-35332: null pointer dereference when handling ECDH public value in TLS (bsc#1261708). - CVE-2026-35333: integer underflow when handling RADIUS attributes (bsc#1261706). - CVE-2026-35334: possible null pointer dereference in RSA decryption (bsc#1261720). - CVE-2026-47895: double-free when destroying certain cloned identities (bsc#1266360).
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This update for strongSwan fixes seven distinct vulnerabilities (CVE-2026-35328 through CVE-2026-35334) and one additional CVE (CVE-2026-47895). The issues include an infinite loop triggered by supported versions TLS extension, null pointer dereferences in PKCS#7 padding processing and ECDH public value handling, integer underflows in EAP-SIM/AKA and RADIUS attribute processing, acceptance of certificates violating name constraints, a possible null pointer dereference during RSA decryption, and a double-free vulnerability when destroying certain cloned identities. These vulnerabilities affect strongSwan version 5.9.11-150500.5.23.2 on the aarch64 platform as distributed by SUSE. No CVSS scores are provided. The vulnerabilities collectively pose a high severity risk.
Potential Impact
The vulnerabilities can cause denial of service conditions such as infinite loops and crashes due to null pointer dereferences and double-free errors. Acceptance of certificates violating name constraints may weaken authentication guarantees. Integer underflows in protocol attribute handling could lead to unexpected behavior or memory corruption. These issues collectively undermine the reliability and security of strongSwan VPN deployments on affected versions.
Mitigation Recommendations
A security update is available from the SUSE Product Security Team that addresses these vulnerabilities in strongSwan version 5.9.11-150500.5.23.2 for aarch64. Users should apply the official SUSE patch or update to the fixed version as provided by SUSE. Patch status is confirmed by the vendor advisory. No cloud service remediation applies as this is not a cloud service. There are no known exploits in the wild at this time.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_base
- Csaf Version
- 2.0
- Publisher
- Bundesamt für Sicherheit in der Informationstechnik
- Advisory Id
- WID-SEC-W-2026-1247
- Cve Count
- 7
- Additional Cves
- ["CVE-2026-35329","CVE-2026-35331","CVE-2026-35332","CVE-2026-35333","CVE-2026-35334","CVE-2026-35330"]
- Cvss Version
- null
Threat ID: 6a18abace29bf47b5028aac0
Added to database: 05/28/2026, 20:55:08 UTC
Last enriched: 06/20/2026, 21:08:44 UTC
Last updated: 07/31/2026, 12:27:29 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.