CVE-2018-10811: High severity strongSwan Strongswan vulnerability
Published Jun 19, 2018
·Updated
Last updated 25 August 2025
Other sources
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
— Launchpad
Affected Software
8 affected componentsFixes available
strongSwan Strongswan>=5.0.1<5.6.3
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Fedoraproject Fedora=28
debian/strongswan
5.9.1-1+deb11u45.9.1-1+deb11u55.9.8-5+deb12u26.0.1-6+deb13u26.0.4-1
Remediation
Patch Available
Event History
Jun 19, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 5, 2025
Data Sourced
via Ubuntu·08:35 PM
RemedyDescriptionSeverityAffected Software
Feb 20, 2026
Data Sourced
via Debian·03:57 PM
DescriptionAffected Software
Data Sourced
via Launchpad·03:58 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this strongSwan vulnerability?
The vulnerability ID is CVE-2018-10811.
2
What is the severity rating of CVE-2018-10811?
The severity rating of CVE-2018-10811 is high (7.5).
3
How does CVE-2018-10811 allow for a Denial of Service (DoS) attack?
CVE-2018-10811 allows for a DoS attack due to missing initialization of a variable in strongSwan version 5.6.0 and older.
4
Which versions of strongSwan are affected by CVE-2018-10811?
strongSwan versions 5.6.0 and older are affected by CVE-2018-10811.
5
How can I fix the vulnerability CVE-2018-10811 in strongSwan?
To fix the vulnerability CVE-2018-10811, update strongSwan to version 5.6.2-1ubuntu2.2 (for Ubuntu) or 5.7.2-1+deb10u2 (for Debian), or apply the necessary patches.