
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35332 is a null pointer dereference vulnerability in strongSwan affecting SUSE Linux SLES15 and SLES_SAP15 distributions. The flaw occurs during TLS processing when handling an ECDH (Elliptic Curve Diffie-Hellman) public value, and can be triggered by remote users who are able to initiate or influence TLS connections. The CVE was first detected in Feedly threat intelligence on April 22, 2026, with vendor advisories from SUSE, Debian, and Ubuntu following shortly after. The vulnerability is estimated as HIGH severity by Feedly, though an official CVSS score has not yet been published as the CVE remains in Reserved status (Feedly, SUSE Advisory).
The root cause is a null pointer dereference (CWE-476) in strongSwan's TLS implementation, specifically triggered when processing an ECDH public value during a TLS handshake. An attacker capable of sending crafted TLS messages to a vulnerable strongSwan instance can cause the daemon to dereference a null pointer, likely resulting in a crash. The attack vector is network-based and does not appear to require authentication, as any remote party capable of initiating TLS processing with the affected system can trigger the condition. The vulnerability is specific to the strongSwan packages as shipped in SUSE SLES15 and SLES_SAP15, and has also been addressed in Debian and Ubuntu distributions (SUSE Advisory, Debian DSA).
Successful exploitation causes a null pointer dereference in the strongSwan IKE daemon, leading to a process crash and denial of service. Since strongSwan is commonly used for IPsec VPN and secure network tunneling, a crash can disrupt VPN connectivity and network access for all users relying on the affected service. There is no current evidence that this vulnerability enables remote code execution or data exfiltration; the primary impact is availability (Feedly, SUSE Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-35332 at this time. The CVE remains in Reserved status, and no EPSS score or CISA KEV catalog entry has been published. Detection plugins are available from Nessus (plugin IDs 309664, 309912, 313690, 313701, 315970, 318184) and Qualys (detection ID 6275330), indicating active scanner coverage (Feedly, Tenable).
charon) daemon crashes or restarts in system logs (e.g., /var/log/syslog, journalctl -u strongswan); segmentation fault or null pointer dereference messages associated with the charon process.charon or ipsec process without administrator action; core dump files generated by the strongSwan daemon.SUSE has released updated strongSwan packages for SLES15 and SLES_SAP15 via advisories SUSE-SU-2026:1762-1 and SUSE-SU-2026:2197-1; administrators should apply these updates immediately (SUSE Advisory, SUSE Advisory 2). Debian has issued DSA-6227-1 and Ubuntu has released USN-8196-1 and USN-8196-2 with patched strongSwan packages for their respective distributions (Debian DSA, Ubuntu USN-8196-1). As a temporary workaround where patching is not immediately possible, consider restricting network access to strongSwan TLS endpoints using firewall rules to limit exposure to trusted sources only.
Coverage has been primarily limited to Linux security advisory aggregators and scanner vendors. Pro-Linux.de, LinuxSecurity.com, and LinuxCompatible.org have published summaries of the relevant advisories. Tenable and Qualys have both released detection plugins, indicating prompt scanner community response. No notable researcher commentary or social media discussion has been identified beyond routine advisory tracking (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."