Logo
vulnerabilityCVE-2026-25075
Name
CVE-2026-25075
Source
NVD ( link)Debian ( link)
Description
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
strongswan
Patched

Vulnerability Ratings#


8.7
CVSSv4
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
5.9.14
Patched
buildroot
master
6.0.5
Not Affected
openwrt
master
6.0.7-r1
Not Affected
openwrt
openwrt-25.12
6.0.3-r1
Not Affected
yocto
kirkstone
5.9.13
Not Affected
yocto
master
6.0.6
Not Affected

Resolved with patches#


strongswan (buildroot:2025.02.x)

#
Title
Author
Resolve
1
eap-ttls: Prevent crash if AVP length header field is invalid
Tobias Brunner <tobias@strongswan.org>
CVE-2026-25075

strongswan (yocto:scarthgap)

#
Title
Author
Resolve
1
eap-ttls: Prevent crash if AVP length header field is invalid
Tobias Brunner <tobias@strongswan.org>
CVE-2026-25075