
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35334 is a null pointer dereference vulnerability in the RSA decryption implementation of the strongSwan VPN package, affecting SUSE Linux SLES15 and SLES_SAP15 systems that have not applied the relevant security update. The CVE is currently in "Reserved" status, indicating it was recently assigned and full NVD details are pending. It was first detected and reported around April 22, 2026, with vendor advisories from SUSE, Debian, and Ubuntu following shortly after (Feedly, SUSE Advisory). Feedly estimates the severity as HIGH, consistent with the potential for denial-of-service or worse from a null pointer dereference in a cryptographic subsystem (Feedly).
The vulnerability is rooted in a null pointer dereference (CWE-476) occurring during RSA decryption operations within the strongSwan IKE daemon. A null pointer dereference in a cryptographic code path can be triggered when the software fails to validate a pointer before dereferencing it during the processing of RSA-encrypted data, such as during IKE handshake operations. This class of bug typically requires an attacker to send a specially crafted IKE or certificate message to the strongSwan daemon, causing it to attempt to dereference a null pointer and crash. Detection plugins from Nessus (IDs: 309664, 309912, 313701, 313690, 315970) and Qualys (ID: 6275315) have been published to identify unpatched systems (Feedly, Tenable).
Successful exploitation of this vulnerability would most likely result in a crash of the strongSwan IKE daemon (charon), causing a denial of service for all VPN connections managed by the affected host. Since strongSwan is commonly used for IPsec VPN gateways, exploitation could disrupt secure communications for all connected clients and potentially expose network segments that rely on the VPN for access control. Depending on the deployment context, repeated exploitation could be used to persistently deny VPN service or, in edge cases, may have further implications if the crash leads to unsafe state handling (Feedly, SUSE Advisory).
As of the available data, there is no public evidence of active in-the-wild exploitation or published proof-of-concept exploit code for CVE-2026-35334. The CVE remains in "Reserved" status, and no CISA KEV catalog listing has been identified. The vulnerability is network-reachable (strongSwan listens on UDP 500/4500 by default), which lowers the bar for exploitation by unauthenticated remote attackers who can send crafted IKE packets. Multiple scanner plugins (Nessus, Qualys) have been released to detect unpatched systems, indicating active scanning interest from the security community (Feedly, Tenable).
/var/log/messages or journalctl output (e.g., segmentation fault or null pointer dereference stack traces from charon); repeated IKE negotiation failures logged in /var/log/strongswan/charon.log.charon process; core dump files generated in the strongSwan working directory.core or charon.core) in /var/run/strongswan/ or the system's core dump directory (Feedly).SUSE has released security updates addressing this vulnerability for SLES15 and SLES_SAP15 via advisories SUSE-SU-2026:1762-1 and SUSE-SU-2026:2197-1; administrators should apply these patches immediately (SUSE Advisory, SUSE Advisory 2). Debian has issued DSA-6227-1 and Ubuntu has released USN-8196-1 and USN-8196-2 for their respective strongSwan packages (Debian Advisory, Linux Security). As a temporary workaround where patching is not immediately possible, administrators can restrict access to IKE ports (UDP 500/4500) via firewall rules to trusted IP ranges, or temporarily disable the strongSwan service if VPN connectivity is not critical.
The vulnerability received coverage from Linux security news aggregators including LinuxSecurity.com, LinuxCompatible.org, and Pro-Linux.de, reflecting standard community attention for a VPN daemon vulnerability (Linux Security, Pro-Linux). A blog post on Portal Linux Ferramentas highlighted the denial-of-service risk for strongSwan VPN servers (Portal Linux). No notable researcher commentary or significant social media discussion beyond standard advisory distribution has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."