Executive brief
strongSwan is an open-source VPN implementation widely deployed in corporate networks, routers, and embedded systems to manage IPsec connections. A memory leak in the IKE message logging functionality allows an attacker to send specially crafted VPN negotiation messages that leak memory with each message processed. By sending enough messages, an attacker can exhaust system memory and cause the VPN service to stop responding, disrupting secure communications for all users relying on that VPN gateway.
Technical details
The vulnerability is a resource exhaustion flaw (CWE-400) in the message_t::parse_body() and get_string() functions of libcharon. When converting IKE messages to string representation for logging, the code obtains payload enumerators via create_payload_enumerator() but fails to destroy them if the fixed-size stack buffer is exhausted during snprintf() operations. An attacker can craft messages with many unknown payloads or configuration attributes whose string representation exceeds the buffer, triggering the early return without enumerator cleanup. This leaks up to 80 bytes per message (40 bytes in versions prior to 4.4.1). The vulnerability requires network reachability to the IKE service but no authentication. Accumulated memory leaks eventually cause denial of service through memory exhaustion. The issue is fixed in strongSwan 6.1.0 and patches are available for older versions.
Affected products
- strongSwan strongSwan 4.1.2 through 6.0.7
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in strongSwan 6.1.0; patches available for older versions