CVE-2026-35334
strongSwan vulnerability analysis and mitigation

Overview

CVE-2026-35334 is a null pointer dereference vulnerability in the RSA decryption implementation of the strongSwan VPN package, affecting SUSE Linux SLES15 and SLES_SAP15 systems that have not applied the relevant security update. The CVE is currently in "Reserved" status, indicating it was recently assigned and full NVD details are pending. It was first detected and reported around April 22, 2026, with vendor advisories from SUSE, Debian, and Ubuntu following shortly after (Feedly, SUSE Advisory). Feedly estimates the severity as HIGH, consistent with the potential for denial-of-service or worse from a null pointer dereference in a cryptographic subsystem (Feedly).

Technical details

The vulnerability is rooted in a null pointer dereference (CWE-476) occurring during RSA decryption operations within the strongSwan IKE daemon. A null pointer dereference in a cryptographic code path can be triggered when the software fails to validate a pointer before dereferencing it during the processing of RSA-encrypted data, such as during IKE handshake operations. This class of bug typically requires an attacker to send a specially crafted IKE or certificate message to the strongSwan daemon, causing it to attempt to dereference a null pointer and crash. Detection plugins from Nessus (IDs: 309664, 309912, 313701, 313690, 315970) and Qualys (ID: 6275315) have been published to identify unpatched systems (Feedly, Tenable).

Impact

Successful exploitation of this vulnerability would most likely result in a crash of the strongSwan IKE daemon (charon), causing a denial of service for all VPN connections managed by the affected host. Since strongSwan is commonly used for IPsec VPN gateways, exploitation could disrupt secure communications for all connected clients and potentially expose network segments that rely on the VPN for access control. Depending on the deployment context, repeated exploitation could be used to persistently deny VPN service or, in edge cases, may have further implications if the crash leads to unsafe state handling (Feedly, SUSE Advisory).

Exploitability

As of the available data, there is no public evidence of active in-the-wild exploitation or published proof-of-concept exploit code for CVE-2026-35334. The CVE remains in "Reserved" status, and no CISA KEV catalog listing has been identified. The vulnerability is network-reachable (strongSwan listens on UDP 500/4500 by default), which lowers the bar for exploitation by unauthenticated remote attackers who can send crafted IKE packets. Multiple scanner plugins (Nessus, Qualys) have been released to detect unpatched systems, indicating active scanning interest from the security community (Feedly, Tenable).

Exploitation steps

  1. Reconnaissance: Identify internet-facing hosts running strongSwan on SUSE SLES15/SLES_SAP15, Debian, or Ubuntu using network scanners (e.g., Shodan, Censys) targeting UDP ports 500 and 4500 (IKE/IPsec).
  2. Fingerprint target: Confirm the strongSwan version and that the security patch has not been applied, using banner grabbing or vulnerability scanners (Nessus plugin 309664, Qualys 6275315).
  3. Craft malicious IKE/RSA payload: Construct a specially crafted IKEv1 or IKEv2 message that triggers the RSA decryption code path with input designed to cause a null pointer dereference (e.g., a malformed certificate or encrypted payload).
  4. Send payload: Transmit the crafted packet to the target's UDP port 500 or 4500 without requiring prior authentication.
  5. Trigger crash: The strongSwan charon daemon dereferences a null pointer during RSA decryption, causing a process crash and denial of service for all active and new VPN sessions (Feedly).

Indicators of compromise

  • Network: Unexpected or malformed IKE packets (UDP 500/4500) from unknown external sources; repeated connection attempts with unusual certificate or payload structures.
  • Logs: strongSwan charon daemon crash entries in /var/log/messages or journalctl output (e.g., segmentation fault or null pointer dereference stack traces from charon); repeated IKE negotiation failures logged in /var/log/strongswan/charon.log.
  • Process: Unexpected termination and restart of the charon process; core dump files generated in the strongSwan working directory.
  • File System: Presence of core dump files (e.g., core or charon.core) in /var/run/strongswan/ or the system's core dump directory (Feedly).

Mitigation and workarounds

SUSE has released security updates addressing this vulnerability for SLES15 and SLES_SAP15 via advisories SUSE-SU-2026:1762-1 and SUSE-SU-2026:2197-1; administrators should apply these patches immediately (SUSE Advisory, SUSE Advisory 2). Debian has issued DSA-6227-1 and Ubuntu has released USN-8196-1 and USN-8196-2 for their respective strongSwan packages (Debian Advisory, Linux Security). As a temporary workaround where patching is not immediately possible, administrators can restrict access to IKE ports (UDP 500/4500) via firewall rules to trusted IP ranges, or temporarily disable the strongSwan service if VPN connectivity is not critical.

Community reactions

The vulnerability received coverage from Linux security news aggregators including LinuxSecurity.com, LinuxCompatible.org, and Pro-Linux.de, reflecting standard community attention for a VPN daemon vulnerability (Linux Security, Pro-Linux). A blog post on Portal Linux Ferramentas highlighted the denial-of-service risk for strongSwan VPN servers (Portal Linux). No notable researcher commentary or significant social media discussion beyond standard advisory distribution has been identified.

Additional resources


SourceThis report was generated using AI

Related strongSwan vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47895HIGH7.5
  • strongSwan logostrongSwan
  • perl-vici
NoYesAug 22, 2026
CVE-2026-35334NONEN/A
  • strongSwan logostrongSwan
  • strongswan-sqlite
NoYesApr 22, 2026
CVE-2026-35333NONEN/A
  • strongSwan logostrongSwan
  • strongswan-doc
NoYesApr 22, 2026
CVE-2026-35332NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesApr 22, 2026
CVE-2026-35331NONEN/A
  • strongSwan logostrongSwan
  • strongswan-fips
NoYesApr 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management