CVE-2026-25075: strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow
strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow
Other sources
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
strongSwanto a version that resolves this vulnerability.Fixed in 6.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25075?
CVE-2026-25075 has a high severity rating as it allows unauthenticated remote attackers to perform denial of service attacks.
How do I fix CVE-2026-25075?
To fix CVE-2026-25075, upgrade strongSwan to version 6.0.5 or later.
Which versions of strongSwan are affected by CVE-2026-25075?
CVE-2026-25075 affects strongSwan versions from 4.5.0 up to, but not including, 6.0.5.
What type of attack does CVE-2026-25075 enable?
CVE-2026-25075 enables denial of service attacks through crafted AVP data with invalid length fields.
Can CVE-2026-25075 be exploited remotely?
Yes, CVE-2026-25075 can be exploited remotely by unauthenticated attackers.