CVE-2026-78126: Null Pointer Dereference
Published Sep 11, 2026
·Updated
strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
Affected Software
1 affected component
strongSwan Strongswan>=4.1.10<=6.0.7
Event History
Sep 11, 2026
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
strongSwan versions 4.1.10 through 6.0.7 are affected when the eap-aka plugin is present and reachable. The issue can cause a denial of service through a NULL pointer dereference.
2
What does an attacker need to exploit this issue?
The vector is network-based and requires no privileges or user interaction. Exploitation has high attack complexity according to the provided CVSS vector.
3
Is a fix available?
The referenced strongSwan 6.1.0 release is available. Versions through 6.0.7 are listed as affected.