USN-8789-1: strongSwan vulnerabilities
It was discovered that strongSwan incorrectly handled PKCS#7 containers
in the openssl plugin. A remote attacker could possibly use this issue
to cause strongSwan to crash, resulting in a denial of service.
(CVE-2026-78123)
It was discovered that strongSwan incorrectly handled memory when
enumerating certificates in PKCS#7 containers in the openssl plugin.
A remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2026-78124)
It was discovered that strongSwan incorrectly handled
AKA-Synchronization-Failure messages in the eap-aka plugin. A remote
attacker could possibly use this issue to cause strongSwan to crash,
resulting in a denial of service. (CVE-2026-78126)
It was discovered that strongSwan incorrectly handled memory when
stringifying IKE messages. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2026-78127)
It was discovered that strongSwan incorrectly handled PKCS#5 decryption.
A remote attacker could possibly use this issue to cause strongSwan to
consume excessive resources, leading to a denial of service.
(CVE-2026-78129)
It was discovered that strongSwan incorrectly handled attribute
certificates in the x509 plugin when the issuer name was missing. A
remote attacker could possibly use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2026-78130)
It was discovered that strongSwan incorrectly handled memory when
parsing attribute certificates in the x509 plugin. A remote attacker
could possibly use this issue to obtain sensitive information.
(CVE-2026-78131)
It was discovered that strongSwan incorrectly handled attribute
certificates containing ietfAttrSyntax values in the x509 plugin. A
remote attacker could possibly use this issue to cause strongSwan to
consume excessive resources, leading to a denial of service.
(CVE-2026-78132)
It was discovered that strongSwan incorrectly handled IKEv2 rekeying
collisions with multi-key exchange. A remote attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-78133)
It was discovered that strongSwan incorrectly validated inner EAP
method authentication details in the eap-ttls and eap-peap plugins.
An authenticated user could possibly use this issue to bypass
authentication. (CVE-2026-78134)
It was discovered that strongSwan incorrectly handled CREATE_CHILD_SA
requests on unestablished IKE_SAs. A remote attacker could possibly
use this issue to bypass authentication. (CVE-2026-78135)