CVE-2026-78127: Low severity strongSwan libcharon vulnerability
libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using strongSwan libcharon versions 4.1.2 through 6.0.7 are affected. The issue is in the IKE message parser.
What access does an attacker need to exploit this?
The CVSS vector indicates the issue is remotely reachable over the network and requires no privileges or user interaction. Exploitation has high attack complexity.
What is the expected impact?
The listed impact is limited to availability, with no indicated confidentiality or integrity impact. The issue is a missing memory release after its effective lifetime in IKE message parsing.
What version should be used to remediate the issue?
The affected range ends at strongSwan 6.0.7, and the provided release reference is for 6.1.0. Upgrading to the referenced 6.1.0 release addresses exposure to the affected version range.