
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35333 is an integer underflow vulnerability in strongSwan's RADIUS attribute handling, affecting strongSwan packages on SUSE Linux SLES15/SLES_SAP15, as well as Debian and Ubuntu distributions. The vulnerability was first detected in threat intelligence feeds around April 22, 2026, with vendor advisories from SUSE, Debian, and Ubuntu following shortly after. The CVE status is currently listed as "Reserved," and Feedly estimates the severity as HIGH. Affected platforms include SUSE SLES15/SLES_SAP15, Debian, Ubuntu, and FreeBSD (via FreshPorts), with fixes distributed through updated packages (Feedly, SUSE Advisory, Debian DSA).
The root cause is an integer underflow (CWE-191) occurring during the parsing or processing of RADIUS protocol attributes within strongSwan's IKE/VPN daemon. Integer underflows in attribute length or count fields can lead to out-of-bounds memory reads or writes, potentially enabling denial-of-service or, in more severe cases, memory corruption. The vulnerability is present in the strongSwan package as shipped on multiple Linux distributions, and exploitation likely requires the ability to send crafted RADIUS packets to a vulnerable strongSwan instance. A public exploit entry has been observed on Exploit-DB (ID 52586) and referenced via Sploitus and Vulners (Feedly, Exploit-DB, Vulners).
Successful exploitation of this integer underflow could result in a denial-of-service (DoS) condition by crashing the strongSwan daemon, disrupting VPN connectivity for all users relying on the affected system. In more severe scenarios, memory corruption resulting from the underflow could potentially allow an attacker to achieve arbitrary code execution, though the primary documented impact is DoS. Systems using strongSwan with RADIUS-based authentication (common in enterprise VPN deployments) are at elevated risk, and disruption could affect availability of network access controls and remote access infrastructure (Feedly, Radar Offseq).
A public exploit for CVE-2026-35333 has been published on Exploit-DB (exploit ID 52586) and is referenced on Sploitus (PACKETSTORM:222182) and Vulners, indicating the vulnerability is weaponized and accessible to a broad range of threat actors (Exploit-DB, Sploitus). No confirmed in-the-wild exploitation or specific threat actor attribution has been publicly reported as of the latest available data. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no EPSS score is available at this time. Detection plugins are available from Nessus (IDs: 309664, 309912, 313690, 313701, 315970, 318184) and Qualys (ID: 6275325), enabling broad scanner coverage (Feedly).
charon (strongSwan IKE daemon) process logged in /var/log/syslog, /var/log/daemon.log, or strongSwan's own log files; error messages referencing RADIUS attribute parsing failures.charon process; absence of the strongSwan daemon in process listings following a crash.core, charon.core) in the strongSwan working directory or /var/run/ following a crash event.Vendors have released updated packages addressing CVE-2026-35333 across multiple distributions. SUSE has issued advisories SUSE-SU-2026:1762-1 and SUSE-SU-2026:2197-1 for SLES15/SLES_SAP15; Debian has released DSA-6227-1; Ubuntu has issued USN-8196-1 and USN-8196-2; and FreeBSD has published a corresponding update. Administrators should update strongSwan packages to the fixed versions provided by their distribution as the primary remediation. As a temporary workaround, restricting network access to RADIUS-related interfaces and limiting exposure of IKE endpoints to trusted sources can reduce attack surface (SUSE Advisory, Debian DSA, Ubuntu USN-8196-1).
The vulnerability has received coverage from Linux security news aggregators including LinuxSecurity.com and LinuxCompatible.org, as well as the German security news site Pro-Linux.de, indicating broad awareness in the Linux community. Tenable has released multiple Nessus detection plugins (309664, 309912, 313690, 313701, 315970, 318184) and Qualys has added a detection (6275325), reflecting prompt response from the vulnerability management industry. No notable individual researcher commentary or significant social media discussion has been identified beyond standard advisory and scanner coverage (Feedly, Tenable Nessus).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."