CVE-2026-78133: Use After Free
Published Sep 11, 2026
·Updated
libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.
Affected Software
1 affected component
strongSwan libcharon>=6.0.0<=6.0.7
Event History
Sep 11, 2026
CVE Published
via MITRE·01:52 AM
Data Sourced
via MITRE·01:52 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be prioritized for review?
Deployments using strongSwan libcharon versions 6.0.0 through 6.0.7 are affected. Review systems where IKEv2 rekeying is enabled or used.
2
What does an attacker need to exploit this issue?
The vulnerability is network-reachable and requires low privileges. Exploitation has high attack complexity and does not require user interaction.
3
What is the potential impact of successful exploitation?
Successful exploitation may result in high impact to confidentiality, integrity, and availability.
4
How can I determine whether an installation is affected?
Check the installed strongSwan/libcharon version. Versions from 6.0.0 through 6.0.7 fall within the affected range.