strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
References
| Link | Resource |
|---|---|
| https://github.com/strongswan/strongswan/releases/tag/6.1.0 | Patch Release Notes Vendor Advisory |
| https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html | Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-11 02:18
Updated : 2026-09-14 20:09
NVD link : CVE-2026-78124
Mitre link : CVE-2026-78124
CVE.ORG link : CVE-2026-78124
JSON object : View
Products Affected
strongswan
- strongswan
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
