GPU VulnDB

Database/Kernel, userspace & hypervisor

strongSwan: expired pointer dereference in PKCS#7 parsing crashes the IKE daemon

CVSS 5.9CVE-2026-78123Kernel, userspace & hypervisorcurated

Impact

strongSwan 5.0.2 through 6.0.7 dereferences an expired pointer while parsing PKCS#7 structures in the openssl plugin. The record scores this as a remote, unauthenticated availability loss with high attack complexity - a crash of the IKE daemon, not code execution. Where strongSwan terminates site-to-site or management-plane IPsec tunnels into a GPU site, losing charon drops those tunnels until it restarts, which can cut remote management or storage replication paths rather than tenant GPU traffic itself. The advisory does not claim memory disclosure or execution.

Who can reach it

Network, no authentication stated, high complexity: a peer able to reach the IKE listener and deliver a crafted PKCS#7 structure during certificate handling.

What to do

Upgrade to strongSwan 6.1.0, which is the release the project ships the fix in; distribution backports may also be available. Rollout is a daemon restart on the gateway - tunnels renegotiate afterwards, so schedule it with the expectation of a brief IPsec outage rather than a node reboot. Builds that do not use the openssl plugin for PKCS#7 handling are not affected.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.