Eleven Vulnerabilities Fixed
Thanks to improvements in AI-assisted security analysis, the following eleven vulnerabilities were found and fixed. Please refer to the individual advisories for further details.
- CVE-2026-78123 - Fixed a vulnerability in the
opensslplugin related to the processing of PKCS#7 containers that can result in a crash. Affects 5.0.2 and newer. - CVE-2026-78124 - Fixed a vulnerability in the
opensslplugin related to the enumeration of certificates in PKCS#7 containers that can result in memory leaks. Affects 5.0.2 and newer. - CVE-2026-78126 - Fixed a vulnerability in the
eap-akaplugin related to processing an unexpected AKA-Synchronization-Failure that can result in a crash. Affects 4.1.10 and newer. - CVE-2026-78127 - Fixed a vulnerability in
libcharonrelated to the logging of IKE messages that can result in a denial of service via memory exhaustion. Affects 4.1.2 and newer. - CVE-2026-78129 - Fixed a vulnerability in
libstrongswanrelated to the processing of encrypted PKCS#7 containers that can result in a denial of service. Affects 4.6.2 and newer. - CVE-2026-78130 - Fixed a vulnerability in the
x509plugin related to the verification of X.509 attribute certificates that can lead to a denial of service. Affects 4.2.0 and newer. - CVE-2026-78131 - Fixed a vulnerability in the
x509plugin related to the parsing of identities in X.509 attribute certificates that can lead to a denial of service via memory exhaustion. Affects 4.2.0 and newer. - CVE-2026-78132 - Fixed a vulnerability in the
x509plugin related to the parsing of the ietfAttrSyntax ASN.1 type in X.509 attribute certificates that can lead to a denial of service. Affects 5.1.3 and newer. - CVE-2026-78133 - Fixed a vulnerability in
libcharonrelated to the handling of IKEv2 rekeying collisions that can result in a use-after-free and potentially remote code execution. Affects 6.0.0 and newer. - CVE-2026-78134 - Fixed a vulnerability in the
eap-peapandeap-ttlsplugins related to the propagation of authentication details from inner EAP methods that can result in incorrect identity binding and potential authorization bypass. Affects 4.5.0 and newer. - CVE-2026-78135 - Fixed a vulnerability in
libcharonrelated to the handling of CREATE_CHILD_SA requests on unestablished IKE SAs that can result in the creation of a usable Child SA before authentication completes. Affects 5.9.7 and newer.