CVE-2025-62291
published 2026-01-16CVE-2025-62291: In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause…
PriorityP350high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.88%
55.4th percentile
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | strongswan | < strongswan 5.9.8-5+deb12u2 (bookworm) | strongswan 5.9.8-5+deb12u2 (bookworm) |
| strongswan | strongswan | >= 0 < 5.9.1-1+deb11u5 | 5.9.1-1+deb11u5 |
| strongswan | strongswan | >= 0 < 5.9.8-5+deb12u2 | 5.9.8-5+deb12u2 |
| strongswan | strongswan | >= 0 < 6.0.1-6+deb13u2 | 6.0.1-6+deb13u2 |
| strongswan | strongswan | >= 0 < 6.0.3-1 | 6.0.3-1 |
| strongswan | strongswan | >= 4.2.12 < 6.0.3 | 6.0.3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-62291: In the eap-mschapv2 plugin (client-side) in strongSwan before 6
osv·2026-01-16·CVSS 8.1
CVE-2025-62291 [HIGH] CVE-2025-62291: In the eap-mschapv2 plugin (client-side) in strongSwan before 6
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
GHSA
GHSA-p527-wjvq-vxg8: In the eap-mschapv2 plugin (client-side) in strongSwan before 6
ghsa_unreviewed·2026-01-16
CVE-2025-62291 [HIGH] CWE-191 GHSA-p527-wjvq-vxg8: In the eap-mschapv2 plugin (client-side) in strongSwan before 6
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
Red Hat
strongswan: strongSwan: Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 message
vendor_redhat·2026-01-16·CVSS 8.1
CVE-2025-62291 [HIGH] CWE-191 strongswan: strongSwan: Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 message
strongswan: strongSwan: Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 message
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
A flaw was found in the strongSwan eap-mschapv2 plugin (client-side). A remote attacker, specifically a malicious Extensible Authentication Protocol - Microsoft Challenge-Handshake Authentication Protocol version 2 (EAP-MSCHAPv2) server, could exploit this by sending a specially crafted message between 6 and 8 bytes in size. This crafted message can cause an integer underflow, leading to a heap-based buffer overflow. This vulnerability could potentiall
Ubuntu
strongSwan vulnerability
vendor_ubuntu·2025-10-27
CVE-2025-62291 strongSwan vulnerability
Title: strongSwan vulnerability
Summary: strongSwan client could be made to crash or run programs if it received
specially crafted network traffic.
Xu Biang discovered that the strongSwan client incorrectly handled
EAP-MSCHAPv2 failure requests. If a user or automated system were tricked
into connecting to a malicious server, a remote attacker could use this
issue to cause strongSwan to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2025-62291: strongswan - In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious...
vendor_debian·2025·CVSS 8.1
CVE-2025-62291 [HIGH] CVE-2025-62291: strongswan - In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious...
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 5.9.8-5+deb12u2)
bullseye: resolved (fixed in 5.9.1-1+deb11u5)
forky: resolved (fixed in 6.0.3-1)
sid: resolved (fixed in 6.0.3-1)
trixie: resolved (fixed in 6.0.1-6+deb13u2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-62291 strongswan: From CVEorg collector [epel-9]
bugzilla·2026-01-16·CVSS 8.1
CVE-2025-62291 [HIGH] CVE-2025-62291 strongswan: From CVEorg collector [epel-9]
CVE-2025-62291 strongswan: From CVEorg collector [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-ea9af18b11 (strongswan-6.0.6-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea9af18b11
---
FEDORA-EPEL-2026-ea9af18b11 has been pushed to the Fedora EPEL 9 testing repository.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea9af18b11
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
Bugzilla
CVE-2025-62291 strongswan: From CVEorg collector [epel-10]
bugzilla·2026-01-16·CVSS 8.1
CVE-2025-62291 [HIGH] CVE-2025-62291 strongswan: From CVEorg collector [epel-10]
CVE-2025-62291 strongswan: From CVEorg collector [epel-10]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-9b6d13e4b9 (strongswan-6.0.6-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-9b6d13e4b9
---
FEDORA-EPEL-2026-9b6d13e4b9 has been pushed to the Fedora EPEL 10.3 testing repository.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-9b6d13e4b9
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
Bugzilla
CVE-2025-62291 strongswan: From CVEorg collector [epel-8]
bugzilla·2026-01-16·CVSS 8.1
CVE-2025-62291 [HIGH] CVE-2025-62291 strongswan: From CVEorg collector [epel-8]
CVE-2025-62291 strongswan: From CVEorg collector [epel-8]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-2d8dd834d8 (strongswan-6.0.6-1.el8) has been submitted as an update to Fedora EPEL 8.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-2d8dd834d8
---
FEDORA-EPEL-2026-2d8dd834d8 has been pushed to the Fedora EPEL 8 testing repository.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-2d8dd834d8
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
Bugzilla
CVE-2025-62291 strongswan: From CVEorg collector [fedora-43]
bugzilla·2026-01-16·CVSS 8.1
CVE-2025-62291 [HIGH] CVE-2025-62291 strongswan: From CVEorg collector [fedora-43]
CVE-2025-62291 strongswan: From CVEorg collector [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Should be fixed by a rebase to 6.0.4
---
FEDORA-2026-6888affe44 (strongswan-6.0.4-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-6888affe44
---
FEDORA-2026-6888affe44 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-6888affe44`
You can provide feedback for this update here: https://
Wiz
CVE-2025-62291 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2025-62291 [HIGH] CVE-2025-62291 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62291 :
strongSwan vulnerability analysis and mitigation
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
Source : NVD
## 8.1
Score
Published January 16, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
strongSwan
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
strongswan-debugsource
strongswan-libipsec
Sources
NVD
Alpine 3.20, 3.21, 3.22 Severity HIGH Has Fix Added at: Nov 09, 2025
Alpine
Wiz
CVE-2025-9615 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2025-9615 [HIGH] CVE-2025-9615 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-9615 :
strongSwan vulnerability analysis and mitigation
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
Source : NVD
## 3.3
Score
Published January 26, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
strongSwan
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
NetworkManager-config-connectivity-fedora
NetworkManager
Sourc
Wiz
CVE-2026-25075 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2026-25075 [HIGH] CVE-2026-25075 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25075 :
strongSwan vulnerability analysis and mitigation
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
Source : NVD
## 8.7
Score
Published March 23, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
strongSwan
Linux openSUSE
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EP
2026-01-16
Published