PT-2026-47540 · Unknown+2 · Strongswan+2
CVE-2026-47895
·
Published
2026-06-08
·
Updated
2026-08-24
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
strongSwan versions prior to 6.0.7
Description
Identity parsing and cloning are mishandled in the software. Specifically, parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned, which triggers a double-free—a memory corruption issue where the program attempts to free the same memory location twice—once the duplicates are destroyed. A remote attacker could exploit this to cause the system to crash, resulting in a denial of service, or potentially execute arbitrary code.
Recommendations
Update strongSwan to version 6.0.7 or later.
Exploit
Fix
RCE
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Strongswan