Executive brief
strongSwan is an IPsec VPN implementation widely used to establish secure network connections. A memory leak flaw in the x509 certificate plugin can cause progressive memory exhaustion when processing specially crafted attribute certificates received during VPN connection setup, potentially leading to service denial through resource depletion. This affects VPN gateways and clients that receive untrusted attribute certificates from peers.
Technical details
A memory management flaw exists in the x509 plugin's parse_directoryName() and extension parsing functions. When processing GeneralName entries in attribute certificate Holder/Issuer fields (RFC 5755), the parser enumerates identification_t objects but only retains the first one, leaving subsequent entries unreleased. Similarly, multiple AuthorityKeyIdentifier extensions are not properly freed before reassignment. An attacker can send IKEv2 CERT payloads (encoding type 10) containing attribute certificates with many such entries, causing progressive memory leaks. This requires no authentication and affects any strongSwan installation with the x509 plugin loaded (default configuration). Remote code execution is not possible; impact is limited to denial of service via memory exhaustion.
Affected products
- strongSwan strongSwan 4.2.0 through 6.0.7
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: strongSwan 6.1.0 released with fix