Executive brief
strongSwan is an open-source VPN and IPsec implementation used to secure network communications. The x509 plugin contains an infinite loop vulnerability when parsing attribute certificates with malformed group attributes, causing the VPN service to hang and become unavailable. An attacker could exploit this by sending a specially crafted certificate during VPN authentication to trigger a denial of service.
Technical details
The x509 plugin improperly parses the ietfAttrSyntax ASN.1 type in X.509 attribute certificates. Specifically, the SEQUENCE OF CHOICE parsing rules lack proper CHOICE flags, causing the ASN1_OPT handler to skip alternatives without consuming data when none match. This results in an infinite loop when the parser returns to the ASN1_LOOP marker. The vulnerability is triggered when a CERT payload (encoding type 10) with a malformed group attribute is received during IKEv2 handshake. Attack requires network access to the VPN endpoint and ability to send IKE messages. The fix is available in strongSwan 6.1.0 and patches are provided for older versions.
Affected products
- strongSwan strongSwan 5.1.3 through 6.0.7
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in strongSwan 6.1.0