Executive brief
strongSwan is a widely-used VPN and IPsec implementation that processes X.509 certificates for authentication. A memory leak in its PKCS#7 certificate handling can be triggered by sending specially crafted certificate containers in IKEv1 connections, allowing attackers to exhaust server memory and cause service disruption without requiring authentication.
Technical details
The openssl plugin in strongSwan contains a memory leak in its PKCS#7/CMS container handling. When enumerating certificates using CMS_get1_certs(), the refcount is increased for the stack and contained X.509 structures, but the enumerator destructor fails to call sk_X509_pop_free() to release that refcount, leading to memory leaks per certificate processed. The vulnerability is reachable pre-authentication via IKEv1 certificate payloads using PKCS#7 wrapped X.509 encoding; attackers can trigger leaks with crafted containers requiring at least two IKEv1 messages. The issue affects strongSwan 5.0.2 through 6.0.7 and is fixed in version 6.1.0.
Affected products
- strongSwan strongSwan 5.0.2 through 6.0.7
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in version 6.1.0