CVE-2026-35332
strongSwan vulnerability analysis and mitigation

Overview

CVE-2026-35332 is a null pointer dereference vulnerability in strongSwan affecting SUSE Linux SLES15 and SLES_SAP15 distributions. The flaw occurs during TLS processing when handling an ECDH (Elliptic Curve Diffie-Hellman) public value, and can be triggered by remote users who are able to initiate or influence TLS connections. The CVE was first detected in Feedly threat intelligence on April 22, 2026, with vendor advisories from SUSE, Debian, and Ubuntu following shortly after. The vulnerability is estimated as HIGH severity by Feedly, though an official CVSS score has not yet been published as the CVE remains in Reserved status (Feedly, SUSE Advisory).

Technical details

The root cause is a null pointer dereference (CWE-476) in strongSwan's TLS implementation, specifically triggered when processing an ECDH public value during a TLS handshake. An attacker capable of sending crafted TLS messages to a vulnerable strongSwan instance can cause the daemon to dereference a null pointer, likely resulting in a crash. The attack vector is network-based and does not appear to require authentication, as any remote party capable of initiating TLS processing with the affected system can trigger the condition. The vulnerability is specific to the strongSwan packages as shipped in SUSE SLES15 and SLES_SAP15, and has also been addressed in Debian and Ubuntu distributions (SUSE Advisory, Debian DSA).

Impact

Successful exploitation causes a null pointer dereference in the strongSwan IKE daemon, leading to a process crash and denial of service. Since strongSwan is commonly used for IPsec VPN and secure network tunneling, a crash can disrupt VPN connectivity and network access for all users relying on the affected service. There is no current evidence that this vulnerability enables remote code execution or data exfiltration; the primary impact is availability (Feedly, SUSE Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-35332 at this time. The CVE remains in Reserved status, and no EPSS score or CISA KEV catalog entry has been published. Detection plugins are available from Nessus (plugin IDs 309664, 309912, 313690, 313701, 315970, 318184) and Qualys (detection ID 6275330), indicating active scanner coverage (Feedly, Tenable).

Indicators of compromise

  • Logs: Unexpected strongSwan (charon) daemon crashes or restarts in system logs (e.g., /var/log/syslog, journalctl -u strongswan); segmentation fault or null pointer dereference messages associated with the charon process.
  • Process: Repeated restarts of the charon or ipsec process without administrator action; core dump files generated by the strongSwan daemon.
  • Network: Unusual or malformed TLS handshake traffic directed at strongSwan endpoints, particularly involving ECDH key exchange; unexpected connection resets or timeouts on VPN tunnels.

Mitigation and workarounds

SUSE has released updated strongSwan packages for SLES15 and SLES_SAP15 via advisories SUSE-SU-2026:1762-1 and SUSE-SU-2026:2197-1; administrators should apply these updates immediately (SUSE Advisory, SUSE Advisory 2). Debian has issued DSA-6227-1 and Ubuntu has released USN-8196-1 and USN-8196-2 with patched strongSwan packages for their respective distributions (Debian DSA, Ubuntu USN-8196-1). As a temporary workaround where patching is not immediately possible, consider restricting network access to strongSwan TLS endpoints using firewall rules to limit exposure to trusted sources only.

Community reactions

Coverage has been primarily limited to Linux security advisory aggregators and scanner vendors. Pro-Linux.de, LinuxSecurity.com, and LinuxCompatible.org have published summaries of the relevant advisories. Tenable and Qualys have both released detection plugins, indicating prompt scanner community response. No notable researcher commentary or social media discussion has been identified beyond routine advisory tracking (Feedly).

Additional resources


SourceThis report was generated using AI

Related strongSwan vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47895HIGH7.5
  • strongSwan logostrongSwan
  • perl-vici
NoYesAug 22, 2026
CVE-2026-35334NONEN/A
  • strongSwan logostrongSwan
  • strongswan-sqlite
NoYesApr 22, 2026
CVE-2026-35333NONEN/A
  • strongSwan logostrongSwan
  • strongswan-doc
NoYesApr 22, 2026
CVE-2026-35332NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesApr 22, 2026
CVE-2026-35331NONEN/A
  • strongSwan logostrongSwan
  • strongswan-fips
NoYesApr 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management