cbcvebase.
CVE-2026-25075
published 2026-03-23

CVE-2026-25075: strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to…

PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.01%
59.4th percentile
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianstrongswan< strongswan 5.9.8-5+deb12u3 (bookworm)strongswan 5.9.8-5+deb12u3 (bookworm)
msrcazl3_strongswan_5.9.14-8_on_azure_linux_3.0
msrccbl2_strongswan_5.9.10-4_on_cbl_mariner_2.0
strongswanstrongswan>= 0 < 5.9.1-1+deb11u65.9.1-1+deb11u6
strongswanstrongswan>= 0 < 5.9.8-5+deb12u35.9.8-5+deb12u3
strongswanstrongswan>= 0 < 6.0.1-6+deb13u46.0.1-6+deb13u4
strongswanstrongswan>= 0 < 6.0.5-16.0.5-1
strongswanstrongswan>= 4.5.0 < 6.0.56.0.5

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.