CVE-2026-78132
massInfinite Loop DoS in strongSwan x509 Attribute Certificate Parser (5.1.3-6.0.7)
strongSwan 5.1.3 through 6.0.7 contains an unbounded (infinite) loop, CWE-835, in the x509 plugin's parser for X.509 attribute certificates, triggered when it processes the ietfAttrSyntax attribute type. A remote, unauthenticated attacker who can initiate an IKE exchange and present a crafted attribute certificate, for example in the certificate payloads exchanged during authentication, can drive the parser into an endless loop that hangs a charon daemon thread; repeated triggers can exhaust the daemon's worker threads and disrupt VPN services. The impact is denial of service only (CVSS 3.1 7.5, AV:N/AC:L/PR:N/UI:N with high availability impact and no confidentiality or integrity impact), and it affects VPN gateways and clients running the affected versions with the x509 plugin enabled, which is the default in most distributions and appliances. No public proof-of-concept is available, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Administrators running strongSwan 5.1.3-6.0.7 should upgrade to a release newer than 6.0.7 as soon as the patched version is published. As interim mitigation, restrict IKE access (UDP 500 and 4500) to trusted peers to limit who can present crafted certificates, and monitor the charon daemon for hung threads or stalled IKE handshakes; sites that do not use X.509 attribute certificates can verify whether attribute-certificate parsing can be disabled in their build's plugin configuration.
| strongSwan (strongSwan project) strongSwan (x509 plugin, attribute certificate parsing) | 5.1.3 through 6.0.7 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.
- Vendors
- strongswan
- Products
- strongswan
- Weakness
- CWE-835
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.