GPU VulnDB

Database/Kernel, userspace & hypervisor

strongSwan: PKCS#7 certificate enumeration in the openssl plugin leaks memory

CVSS 3.7CVE-2026-78124Kernel, userspace & hypervisorcurated

Impact

strongSwan 5.0.2 through 6.0.7 fails to release memory after PKCS#7 certificate enumeration in the openssl plugin. Repeated unauthenticated IKE exchanges that carry PKCS#7 structures grow the charon daemon's footprint over time, degrading the tunnel endpoint. Operators who run strongSwan to carry management or inter-site traffic between GPU sites feel this as a slow leak on the VPN gateway rather than a crash; the record assigns only a low confidentiality impact (CVSS 3.7) and no availability score. The advisory does not claim key material exposure.

Who can reach it

Network-reachable, no authentication required per the CVSS vector (AV:N/PR:N) - anyone who can reach the IKE listener on the strongSwan gateway, with high attack complexity.

What to do

Upgrade to strongSwan 6.1.0, which carries the fix, and restart the charon daemon; tunnels renegotiate, so schedule it with the VPN's reconnect window in mind. No node reboot is needed. If you cannot upgrade immediately, restrict who can reach the IKE listener and monitor charon memory.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.