USN-8789-1: strongSwan vulnerabilities

Publication date

21 September 2026

Overview

Several security issues were fixed in strongSwan.


Packages

Details

It was discovered that strongSwan incorrectly handled PKCS#7 containers
in the openssl plugin. A remote attacker could possibly use this issue
to cause strongSwan to crash, resulting in a denial of service.
(CVE-2026-78123)

It was discovered that strongSwan incorrectly handled memory when
enumerating certificates in PKCS#7 containers in the openssl plugin.
A remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2026-78124)

It was discovered that strongSwan incorrectly handled
AKA-Synchronization-Failure messages in the eap-aka plugin. A remote
attacker could possibly use this issue to cause strongSwan to crash,
resulting in a denial of service. (CVE-2026-78126)

It was discovered that strongSwan incorrectly handled memory when
stringifying IKE messages. A remote attacker...

It was discovered that strongSwan incorrectly handled PKCS#7 containers
in the openssl plugin. A remote attacker could possibly use this issue
to cause strongSwan to crash, resulting in a denial of service.
(CVE-2026-78123)

It was discovered that strongSwan incorrectly handled memory when
enumerating certificates in PKCS#7 containers in the openssl plugin.
A remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2026-78124)

It was discovered that strongSwan incorrectly handled
AKA-Synchronization-Failure messages in the eap-aka plugin. A remote
attacker could possibly use this issue to cause strongSwan to crash,
resulting in a denial of service. (CVE-2026-78126)

It was discovered that strongSwan incorrectly handled memory when
stringifying IKE messages. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2026-78127)

It was discovered that strongSwan incorrectly handled PKCS#5 decryption.
A remote attacker could possibly use this issue to cause strongSwan to
consume excessive resources, leading to a denial of service.
(CVE-2026-78129)

It was discovered that strongSwan incorrectly handled attribute
certificates in the x509 plugin when the issuer name was missing. A
remote attacker could possibly use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2026-78130)

It was discovered that strongSwan incorrectly handled memory when
parsing attribute certificates in the x509 plugin. A remote attacker
could possibly use this issue to obtain sensitive information.
(CVE-2026-78131)

It was discovered that strongSwan incorrectly handled attribute
certificates containing ietfAttrSyntax values in the x509 plugin. A
remote attacker could possibly use this issue to cause strongSwan to
consume excessive resources, leading to a denial of service.
(CVE-2026-78132)

It was discovered that strongSwan incorrectly handled IKEv2 rekeying
collisions with multi-key exchange. A remote attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-78133)

It was discovered that strongSwan incorrectly validated inner EAP
method authentication details in the eap-ttls and eap-peap plugins.
An authenticated user could possibly use this issue to bypass
authentication. (CVE-2026-78134)

It was discovered that strongSwan incorrectly handled CREATE_CHILD_SA
requests on unestablished IKE_SAs. A remote attacker could possibly
use this issue to bypass authentication. (CVE-2026-78135)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute libstrongswan –  6.0.4-1ubuntu3.2
strongswan –  6.0.4-1ubuntu3.2
24.04 LTS noble libstrongswan –  5.9.13-2ubuntu4.24.04.5
strongswan –  5.9.13-2ubuntu4.24.04.5
22.04 LTS jammy libstrongswan –  5.9.5-2ubuntu2.8
strongswan –  5.9.5-2ubuntu2.8

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›