Database/Kernel, userspace & hypervisor
strongSwan: PKCS#7 certificate enumeration in the openssl plugin leaks memory
Impact
strongSwan 5.0.2 through 6.0.7 fails to release memory after PKCS#7 certificate enumeration in the openssl plugin. Repeated unauthenticated IKE exchanges that carry PKCS#7 structures grow the charon daemon's footprint over time, degrading the tunnel endpoint. Operators who run strongSwan to carry management or inter-site traffic between GPU sites feel this as a slow leak on the VPN gateway rather than a crash; the record assigns only a low confidentiality impact (CVSS 3.7) and no availability score. The advisory does not claim key material exposure.
Who can reach it
Network-reachable, no authentication required per the CVSS vector (AV:N/PR:N) - anyone who can reach the IKE listener on the strongSwan gateway, with high attack complexity.
What to do
Upgrade to strongSwan 6.1.0, which carries the fix, and restart the charon daemon; tunnels renegotiate, so schedule it with the VPN's reconnect window in mind. No node reboot is needed. If you cannot upgrade immediately, restrict who can reach the IKE listener and monitor charon memory.
References
Related entries
- OpenSSH ssh-agent: locking bypass lets a forwarded remote session add tokens and use keysCVE-2026-73281 · OpenSSH ssh-agent (agent locking vs session-bind@openssh.com extension)Low
- Linux kernel mlx5_ib (create QP response): mlx5_ib_create_qp_resp is never initialized in create_qp_common, so creatingCVE-2018-20855 · Linux kernel mlx5_ib (create QP response)Low
- Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selection: Setting Speculative Store Bypass Disable on AMD FamilyCVE-2022-42336 · Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selectionLow
- OpenSSH sshd: restrict keyword in authorized_keys did not cover tunnel forwardingCVE-2026-73283 · OpenSSH sshd (authorized_keys restrict keyword vs tunnel forwarding)Low
- QEMU / KVM / Xen (VENOM): VENOM: out-of-bounds write in the virtual Floppy Disk ControllerCVE-2015-3456 · QEMU / KVM / Xen (VENOM)Low
- Xen (shadow paging): x86 shadow paging arbitrary pointer dereference - host crash or worseCVE-2022-42335 · Xen (shadow paging)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.