CVE-2026-35329
strongSwan vulnerability analysis and mitigation

Overview

CVE-2026-35329 is a null pointer dereference vulnerability in strongSwan, an open-source IPsec-based VPN solution, triggered during the processing of PKCS#7 padding. The flaw primarily impacts SUSE Linux SLES15 and SLES_SAP15 systems running affected versions of strongSwan, and has also prompted security advisories for Debian and Ubuntu distributions. The CVE identifier is currently in "Reserved" status, indicating full NVD details are pending publication. Feedly estimates the severity as HIGH, and the vulnerability has been detected by multiple scanners including Nessus and Qualys (Feedly, SUSE Advisory).

Technical details

The root cause is a null pointer dereference (CWE-476) occurring within strongSwan's PKCS#7 padding processing logic. When strongSwan parses malformed or specially crafted PKCS#7-encoded data — commonly used in IKE certificate handling — a null pointer is dereferenced, potentially causing the daemon to crash. This flaw is reachable remotely via the IKE negotiation process, meaning an unauthenticated remote attacker could send crafted packets to trigger the condition. No public proof-of-concept exploit code has been identified at this time (Feedly, Debian DSA).

Impact

Successful exploitation of this vulnerability would cause the strongSwan IKE daemon (charon) to crash, resulting in a denial of service for all active and pending VPN connections on the affected system. Because strongSwan is commonly used to secure site-to-site and remote-access VPN tunnels, a crash could disrupt critical network connectivity and potentially expose internal network segments that rely on the VPN for isolation. There is no current evidence that this vulnerability enables remote code execution or direct data exfiltration, but repeated exploitation could be used to persistently deny VPN service (Feedly, SUSE Advisory).

Exploitability

There is no confirmed evidence of active in-the-wild exploitation of CVE-2026-35329 at this time, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No public exploit code or weaponized proof-of-concept has been identified. The vulnerability is remotely triggerable without authentication, which elevates its risk profile. EPSS score data is not yet available given the CVE's reserved status (Feedly).

Indicators of compromise

  • Logs: Unexpected crashes or restarts of the charon or strongswan daemon in system logs (/var/log/syslog, /var/log/daemon.log, or journalctl -u strongswan).
  • Process: Absence of the charon process when VPN connectivity is expected; core dump files generated by the strongSwan process in /var/log/ or the working directory.
  • Network: Sudden loss of IKE/IPsec negotiation traffic on UDP ports 500 and 4500; repeated IKE_SA_INIT or IKE_AUTH requests from an external IP immediately preceding a daemon crash.

Mitigation and workarounds

Vendors have released patched packages addressing CVE-2026-35329. SUSE has issued advisories SUSE-SU-2026:1762-1 and SUSE-SU-2026:2197-1 for SLES15 and SLES_SAP15 (SUSE Advisory 1762, SUSE Advisory 2197). Debian has released DSA-6227-1 and Ubuntu has issued USN-8196-1 and USN-8196-2 with updated strongSwan packages (Debian DSA, Ubuntu USN). Administrators should apply the relevant vendor update immediately; as a temporary workaround, restricting inbound IKE traffic (UDP 500/4500) to trusted peers via firewall rules can reduce exposure until patching is complete.

Community reactions

The vulnerability received coverage from Linux security news aggregators including LinuxSecurity.com, LinuxCompatible.org, and the German-language Pro-Linux.de, reflecting broad awareness in the Linux/open-source community. Tenable published multiple Nessus detection plugins (IDs 309664, 309912, 313701, 315970, and others) shortly after disclosure, indicating rapid uptake by the vulnerability management community (Tenable Nessus). No notable individual researcher commentary or significant social media discussion has been identified beyond standard advisory redistribution.

Additional resources


SourceThis report was generated using AI

Related strongSwan vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47895NONEN/A
  • strongSwan logostrongSwan
  • strongswan-libipsec
NoYesJun 08, 2026
CVE-2026-35334NONEN/A
  • strongSwan logostrongSwan
  • strongswan-charon-nm-debuginfo
NoYesApr 22, 2026
CVE-2026-35333NONEN/A
  • strongSwan logostrongSwan
  • strongswan-libipsec
NoYesApr 22, 2026
CVE-2026-35332NONEN/A
  • strongSwan logostrongSwan
  • strongswan-debuginfo
NoYesApr 22, 2026
CVE-2026-35331NONEN/A
  • strongSwan logostrongSwan
  • strongswan-charon-nm
NoYesApr 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management