CVE-2026-47895: Double Free
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/strongswanto a version that resolves this vulnerability.Fixed in 5.9.8-5+deb12u5Fixed in 6.0.1-6+deb13u6Fixed in 6.0.7-1 - Upgrade
Upgrade
strongSwanto a version that resolves this vulnerability.Fixed in 6.0.7
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates network access is required, along with low privileges. No user interaction is required, but exploitation has high attack complexity.
Which deployments are affected?
The issue affects strongSwan versions before 6.0.7. The provided data identifies Debian's strongSwan package, but does not state whether any particular default configuration is affected.
What is the likely impact if exploitation succeeds?
The vulnerability can trigger a double-free when duplicate parsed EAP-Identities are destroyed. The CVSS assessment rates confidentiality, integrity, and availability impacts as high.