Junglewise Threat Intelligence

CVE-2026-78123: strongSwan openssl plugin expired pointer dereference in PKCS#7 parsing

CVE-2026-78123 · Severity: medium · CVSS 5.9 · Published 2026-09-11

Technologies: strongSwan. Vendors: strongSwan.

Executive brief

strongSwan is an open-source IPsec implementation used to establish secure VPN tunnels and encrypted communications. A flaw in the openssl plugin's handling of PKCS#7 certificate containers can cause the service to crash when processing specially crafted PKCS#7 structures. An attacker could exploit this to disrupt VPN connectivity and authentication services.

Technical details

The openssl plugin in strongSwan does not properly initialize stack variables when parsing PKCS#7 signerInfo or recipientInfo structures that use subjectKeyIdentifier encoding instead of issuerAndSerialNumber. When the OpenSSL library function CMS_SignerInfo_get0_signer_id() or CMS_RecipientInfo_ktri_get0_signer_id() encounters subjectKeyIdentifier format, it leaves uninitialized pointers unchanged despite returning success. Subsequent code dereferences these uninitialized pointers via openssl_x509_name2id() and openssl_asn1_str2chunk(), causing a segmentation fault. The vulnerability affects strongSwan 5.0.2 through 6.0.7 and is reachable via IKEv1 connections. Remote code execution is unlikely; the primary impact is denial of service through a crash.

Affected products

  • strongSwan strongSwan 5.0.2 through 6.0.7

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Fixed in strongSwan 6.1.0

References

Related threats