CVE-2025-62291: Integer Underflow
Published Jan 16, 2026
·Updated
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
Affected Software
1 affected component
strongSwan Strongswan<6.0.3
Event History
Jan 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62291?
CVE-2025-62291 is classified as a high severity vulnerability due to the potential for a heap-based buffer overflow.
2
How do I fix CVE-2025-62291?
To fix CVE-2025-62291, upgrade to strongSwan version 6.0.3 or later.
3
What type of vulnerability is CVE-2025-62291?
CVE-2025-62291 is an integer underflow vulnerability that can lead to a heap-based buffer overflow.
4
Which software is affected by CVE-2025-62291?
CVE-2025-62291 affects strongSwan versions prior to 6.0.3.
5
What causes CVE-2025-62291?
CVE-2025-62291 is caused by a crafted message sent by a malicious EAP-MSCHAPv2 server.