CVE-2026-25075
published 2026-03-23CVE-2026-25075: strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.01%
59.4th percentile
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | strongswan | < strongswan 5.9.8-5+deb12u3 (bookworm) | strongswan 5.9.8-5+deb12u3 (bookworm) |
| msrc | azl3_strongswan_5.9.14-8_on_azure_linux_3.0 | — | — |
| msrc | cbl2_strongswan_5.9.10-4_on_cbl_mariner_2.0 | — | — |
| strongswan | strongswan | >= 0 < 5.9.1-1+deb11u6 | 5.9.1-1+deb11u6 |
| strongswan | strongswan | >= 0 < 5.9.8-5+deb12u3 | 5.9.8-5+deb12u3 |
| strongswan | strongswan | >= 0 < 6.0.1-6+deb13u4 | 6.0.1-6+deb13u4 |
| strongswan | strongswan | >= 0 < 6.0.5-1 | 6.0.5-1 |
| strongswan | strongswan | >= 4.5.0 < 6.0.5 | 6.0.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
strongSwan vulnerability
vendor_ubuntu·2026-03-23
CVE-2026-25075 strongSwan vulnerability
Title: strongSwan vulnerability
Summary: strongSwan could be made to consume resources or crash if it received
specially crafted network traffic.
Kazuma Matsumoto discovered that strongSwan incorrectly handled EAP-TTLS
AVPs when using the eap-ttls plugin. An attacker could possibly use this
issue to cause strongSwan to consume resources and crash, resulting in a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow
vendor_msrc·2026-03-10·CVSS 7.5
CVE-2026-25075 [HIGH] CWE-191 strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow
strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow
Mariner: Mariner
VulnCheck: VulnCheck
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-25075: strongswan - strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerabil...
vendor_debian·2026·CVSS 8.7
CVE-2026-25075 [HIGH] CVE-2026-25075: strongswan - strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerabil...
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
Scope: local
bookworm: resolved (fixed in 5.9.8-5+deb12u3)
bullseye: resolved (fixed in 5.9.1-1+deb11u6)
forky: resolved (fixed in 6.0.5-1)
sid: resolved (fixed in 6.0.5-1)
trixie: resolved (fixed in 6.0.1-6+deb13u4)
GHSA
GHSA-frr2-5qjr-h4hw: strongSwan versions 4
ghsa_unreviewed·2026-03-23
CVE-2026-25075 [HIGH] CWE-191 GHSA-frr2-5qjr-h4hw: strongSwan versions 4
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
OSV
CVE-2026-25075: strongSwan versions 4
osv·2026-03-23·CVSS 8.7
CVE-2026-25075 [HIGH] CVE-2026-25075: strongSwan versions 4
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-25075 strongswan: strongSwan: Denial of Service via integer underflow in EAP-TTLS AVP parser [epel-all]
bugzilla·2026-03-24·CVSS 8.7
CVE-2026-25075 [HIGH] CVE-2026-25075 strongswan: strongSwan: Denial of Service via integer underflow in EAP-TTLS AVP parser [epel-all]
CVE-2026-25075 strongswan: strongSwan: Denial of Service via integer underflow in EAP-TTLS AVP parser [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-25075 strongswan: strongSwan: Denial of Service via integer underflow in EAP-TTLS AVP parser [fedora-43]
bugzilla·2026-03-24·CVSS 8.7
CVE-2026-25075 [HIGH] CVE-2026-25075 strongswan: strongSwan: Denial of Service via integer underflow in EAP-TTLS AVP parser [fedora-43]
CVE-2026-25075 strongswan: strongSwan: Denial of Service via integer underflow in EAP-TTLS AVP parser [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-25075 strongswan: strongSwan: Denial of Service via integer underflow in EAP-TTLS AVP parser [fedora-42]
bugzilla·2026-03-24·CVSS 8.7
CVE-2026-25075 [HIGH] CVE-2026-25075 strongswan: strongSwan: Denial of Service via integer underflow in EAP-TTLS AVP parser [fedora-42]
CVE-2026-25075 strongswan: strongSwan: Denial of Service via integer underflow in EAP-TTLS AVP parser [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Hackernews
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
blogs_hackernews·2026-04-06
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there.
One weak spot now spreads wider than before. What starts small can reach a lot of systems fast. New bugs, faster use, less time to react.
That’s this week. Read through it.
## ⚡ Threat of the Week
Axios npm Package Compromised by N. Korean Hackers —Threat actors with ties to North Korea seized control of the npm account belonging to the lead m
Wiz
CVE-2025-62291 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2025-62291 [HIGH] CVE-2025-62291 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62291 :
strongSwan vulnerability analysis and mitigation
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
Source : NVD
## 8.1
Score
Published January 16, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
strongSwan
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
strongswan-debugsource
strongswan-libipsec
Sources
NVD
Alpine 3.20, 3.21, 3.22 Severity HIGH Has Fix Added at: Nov 09, 2025
Alpine
Wiz
CVE-2025-9615 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2025-9615 [HIGH] CVE-2025-9615 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-9615 :
strongSwan vulnerability analysis and mitigation
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
Source : NVD
## 3.3
Score
Published January 26, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
strongSwan
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
NetworkManager-config-connectivity-fedora
NetworkManager
Sourc
Wiz
CVE-2026-25075 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2026-25075 [HIGH] CVE-2026-25075 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25075 :
strongSwan vulnerability analysis and mitigation
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
Source : NVD
## 8.7
Score
Published March 23, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
strongSwan
Linux openSUSE
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EP
https://www.strongswan.org/blog/2026/03/23/strongswan-6.0.5-released.htmlhttps://www.strongswan.org/blog/2026/03/23/strongswan-vulnerability-(cve-2026-25075).htmlhttps://www.vulncheck.com/advisories/strongswan-eap-ttls-avp-parsing-integer-underflowhttps://y637f9qq2x.com/posts/cve-2026-25075/https://lists.debian.org/debian-lts-announce/2026/03/msg00016.html
2026-03-23
Published