In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-22 22:16
Updated : 2026-09-09 16:04
NVD link : CVE-2026-47895
Mitre link : CVE-2026-47895
CVE.ORG link : CVE-2026-47895
JSON object : View
Products Affected
No product.
CWE
CWE-415
Double Free
