CVE-2026-35333
strongSwan vulnerability analysis and mitigation

Overview

CVE-2026-35333 is an integer underflow vulnerability in strongSwan's RADIUS attribute handling, affecting strongSwan packages on SUSE Linux SLES15/SLES_SAP15, as well as Debian and Ubuntu distributions. The vulnerability was first detected in threat intelligence feeds around April 22, 2026, with vendor advisories from SUSE, Debian, and Ubuntu following shortly after. The CVE status is currently listed as "Reserved," and Feedly estimates the severity as HIGH. Affected platforms include SUSE SLES15/SLES_SAP15, Debian, Ubuntu, and FreeBSD (via FreshPorts), with fixes distributed through updated packages (Feedly, SUSE Advisory, Debian DSA).

Technical details

The root cause is an integer underflow (CWE-191) occurring during the parsing or processing of RADIUS protocol attributes within strongSwan's IKE/VPN daemon. Integer underflows in attribute length or count fields can lead to out-of-bounds memory reads or writes, potentially enabling denial-of-service or, in more severe cases, memory corruption. The vulnerability is present in the strongSwan package as shipped on multiple Linux distributions, and exploitation likely requires the ability to send crafted RADIUS packets to a vulnerable strongSwan instance. A public exploit entry has been observed on Exploit-DB (ID 52586) and referenced via Sploitus and Vulners (Feedly, Exploit-DB, Vulners).

Impact

Successful exploitation of this integer underflow could result in a denial-of-service (DoS) condition by crashing the strongSwan daemon, disrupting VPN connectivity for all users relying on the affected system. In more severe scenarios, memory corruption resulting from the underflow could potentially allow an attacker to achieve arbitrary code execution, though the primary documented impact is DoS. Systems using strongSwan with RADIUS-based authentication (common in enterprise VPN deployments) are at elevated risk, and disruption could affect availability of network access controls and remote access infrastructure (Feedly, Radar Offseq).

Exploitability

A public exploit for CVE-2026-35333 has been published on Exploit-DB (exploit ID 52586) and is referenced on Sploitus (PACKETSTORM:222182) and Vulners, indicating the vulnerability is weaponized and accessible to a broad range of threat actors (Exploit-DB, Sploitus). No confirmed in-the-wild exploitation or specific threat actor attribution has been publicly reported as of the latest available data. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no EPSS score is available at this time. Detection plugins are available from Nessus (IDs: 309664, 309912, 313690, 313701, 315970, 318184) and Qualys (ID: 6275325), enabling broad scanner coverage (Feedly).

Exploitation steps

  1. Reconnaissance: Identify systems running strongSwan with RADIUS authentication enabled, using network scanning tools (e.g., Shodan, Censys, or nmap) to locate IKE/VPN endpoints on UDP port 500 or 4500.
  2. Craft malicious RADIUS packet: Construct a RADIUS attribute packet with a malformed length or count field designed to trigger an integer underflow in strongSwan's attribute parsing code.
  3. Deliver payload: Send the crafted RADIUS packet to the target strongSwan instance, either directly (if RADIUS is network-accessible) or via a RADIUS server that relays to strongSwan.
  4. Trigger underflow: The integer underflow causes incorrect memory calculations, leading to out-of-bounds access — resulting in a crash (DoS) of the strongSwan daemon or, in edge cases, memory corruption.
  5. Achieve objective: At minimum, the VPN/IKE daemon crashes, denying service to legitimate users. In more advanced exploitation, memory corruption may be leveraged for further code execution (Exploit-DB, Feedly).

Indicators of compromise

  • Network: Unexpected or malformed RADIUS packets (unusual attribute lengths or counts) directed at strongSwan endpoints; anomalous traffic on UDP ports 500/4500 from untrusted sources.
  • Logs: Repeated crashes or restarts of the charon (strongSwan IKE daemon) process logged in /var/log/syslog, /var/log/daemon.log, or strongSwan's own log files; error messages referencing RADIUS attribute parsing failures.
  • Process: Unexpected termination or core dumps of the charon process; absence of the strongSwan daemon in process listings following a crash.
  • File System: Core dump files (e.g., core, charon.core) in the strongSwan working directory or /var/run/ following a crash event.

Mitigation and workarounds

Vendors have released updated packages addressing CVE-2026-35333 across multiple distributions. SUSE has issued advisories SUSE-SU-2026:1762-1 and SUSE-SU-2026:2197-1 for SLES15/SLES_SAP15; Debian has released DSA-6227-1; Ubuntu has issued USN-8196-1 and USN-8196-2; and FreeBSD has published a corresponding update. Administrators should update strongSwan packages to the fixed versions provided by their distribution as the primary remediation. As a temporary workaround, restricting network access to RADIUS-related interfaces and limiting exposure of IKE endpoints to trusted sources can reduce attack surface (SUSE Advisory, Debian DSA, Ubuntu USN-8196-1).

Community reactions

The vulnerability has received coverage from Linux security news aggregators including LinuxSecurity.com and LinuxCompatible.org, as well as the German security news site Pro-Linux.de, indicating broad awareness in the Linux community. Tenable has released multiple Nessus detection plugins (309664, 309912, 313690, 313701, 315970, 318184) and Qualys has added a detection (6275325), reflecting prompt response from the vulnerability management industry. No notable individual researcher commentary or significant social media discussion has been identified beyond standard advisory and scanner coverage (Feedly, Tenable Nessus).

Additional resources


SourceThis report was generated using AI

Related strongSwan vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47895HIGH7.5
  • strongSwan logostrongSwan
  • perl-vici
NoYesAug 22, 2026
CVE-2026-35334NONEN/A
  • strongSwan logostrongSwan
  • strongswan-sqlite
NoYesApr 22, 2026
CVE-2026-35333NONEN/A
  • strongSwan logostrongSwan
  • strongswan-doc
NoYesApr 22, 2026
CVE-2026-35332NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesApr 22, 2026
CVE-2026-35331NONEN/A
  • strongSwan logostrongSwan
  • strongswan-fips
NoYesApr 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management