Database/Kernel, userspace & hypervisor
strongSwan: expired pointer dereference in PKCS#7 parsing crashes the IKE daemon
Impact
strongSwan 5.0.2 through 6.0.7 dereferences an expired pointer while parsing PKCS#7 structures in the openssl plugin. The record scores this as a remote, unauthenticated availability loss with high attack complexity - a crash of the IKE daemon, not code execution. Where strongSwan terminates site-to-site or management-plane IPsec tunnels into a GPU site, losing charon drops those tunnels until it restarts, which can cut remote management or storage replication paths rather than tenant GPU traffic itself. The advisory does not claim memory disclosure or execution.
Who can reach it
Network, no authentication stated, high complexity: a peer able to reach the IKE listener and deliver a crafted PKCS#7 structure during certificate handling.
What to do
Upgrade to strongSwan 6.1.0, which is the release the project ships the fix in; distribution backports may also be available. Rollout is a daemon restart on the gateway - tunnels renegotiate afterwards, so schedule it with the expectation of a brief IPsec outage rather than a node reboot. Builds that do not use the openssl plugin for PKCS#7 handling are not affected.
References
Related entries
- Linux kernel (ALSA usb-audio): Out-of-bounds access for Extigy/Mbox devicesCVE-2024-53197 · Linux kernel (ALSA usb-audio)Medium
- Linux kernel (drivers/pci): Enabling or disabling SR-IOV virtual functions was not serialised against PCI hotplug, soCVE-2025-40219 · Linux kernel (drivers/pci)Medium
- Intel CPU (L1TF / Foreshadow-NG): L1 Terminal Fault: a guest reads any data present in the L1 data cache, includingCVE-2018-3646 · Intel CPU (L1TF / Foreshadow-NG)Medium
- Intel x86-64 CPUs (Ivy Bridge onward); Windows and Linux kernel entry paths: The kernel's syscall/interrupt entry pathCVE-2019-1125 · Intel x86-64 CPUs (Ivy Bridge onward); Windows and Linux kernel entry pathsMedium
- AMD CPU (Branch Type Confusion): Non-Retbleed branch type confusion - speculative cross-domain leakCVE-2022-23825 · AMD CPU (Branch Type Confusion)Medium
- AMD CPU (Retbleed): Retbleed: arbitrary speculative code execution via return instructionsCVE-2022-29900 · AMD CPU (Retbleed)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.