PT-2026-47540 · Unknown+2 · Strongswan+2

CVE-2026-47895

·

Published

2026-06-08

·

Updated

2026-08-24

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions strongSwan versions prior to 6.0.7
Description Identity parsing and cloning are mishandled in the software. Specifically, parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned, which triggers a double-free—a memory corruption issue where the program attempts to free the same memory location twice—once the duplicates are destroyed. A remote attacker could exploit this to cause the system to crash, resulting in a denial of service, or potentially execute arbitrary code.
Recommendations Update strongSwan to version 6.0.7 or later.

Exploit

Fix

RCE

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97377
CVE-2026-47895
OPENSUSE-SU-2026:11005-1
OPENSUSE-SU-2026:21092-1
SUSE-SU-2026:22168-1
SUSE-SU-2026:2312-1
SUSE-SU-2026:2368-1
SUSE-SU-2026:2459-1
USN-8407-1

Affected Products

Linuxmint
Ubuntu
Strongswan