Executive brief
strongSwan is an open-source IPsec VPN implementation used by organizations to create secure tunnels for network traffic. The x509 plugin, which handles certificate validation, contains a flaw that crashes when processing specially crafted attribute certificates, causing denial of service and interrupting VPN connectivity.
Technical details
A NULL pointer dereference exists in the x509 plugin's attribute certificate validation code. Specifically, the issued_by() and has_issuer() methods unconditionally dereference the issuerName field without checking if it is NULL; per ASN.1 specification, this field is optional in attribute certificates. An attacker with network access can craft an attribute certificate with a missing issuerName field and provide it to strongSwan for validation, triggering a crash in the acert plugin's certificate validation flow. The vulnerability requires the x509 and acert plugins to be loaded (x509 is loaded by default). Remote code execution is not possible; the impact is limited to denial of service. The fix is available in strongSwan 6.1.0 released 2026-09-07, with patches available for versions 5.1.3 and newer.
Affected products
- strongSwan strongSwan 4.2.0 through 6.0.7
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in strongSwan 6.1.0
- 2026-09-11: advisory: CVE-2026-78130 published on NVD