CVE-2026-47895
EUVD-2026-6460222.08.2026, 22:16
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| strongswan | strongswan | 4.3.3 ≤ 𝑥 < 6.0.7 | CNA |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| strongswan |
| ||||||||
| strongswan-doc |
| ||||||||
| strongswan-hmac |
| ||||||||
| strongswan-ipsec |
| ||||||||
| strongswan-libs0 |
|
Common Weakness Enumeration