CVE-2026-47895
strongSwan vulnerability analysis and mitigation

Overview

CVE-2026-47895 is a double-free vulnerability in strongSwan's libstrongswan library related to the incorrect cloning of certain identities, which can allow a remote attacker to cause a denial of service (crash) or potentially execute arbitrary code. The flaw affects strongSwan versions 4.3.3 and newer and was fixed in the upstream release 6.0.7 on June 8, 2026 (strongSwan 6.0.7). Ubuntu issued security notice USN-8407-1 on the same date, covering Ubuntu 22.04 LTS, 24.04 LTS, 25.10, and 26.04 LTS (Ubuntu USN-8407-1). Feedly estimates the severity as HIGH, and the CVE was discovered by Elliott Childre (Ubuntu USN-8407-1).

Technical details

The root cause is a double-free memory corruption flaw (CWE-415) in libstrongswan's identity cloning logic, present since version 4.3.3. When strongSwan processes specially crafted network traffic, the flawed cloning routine can free the same memory region twice, corrupting heap state. This is exploitable remotely without authentication, as the vulnerable code path can be triggered during IKE negotiation by sending malformed identity payloads. The vulnerability was credited to researcher Elliott Childre and patched in upstream commit referenced in the 6.0.7 release (strongSwan 6.0.7, Ubuntu USN-8407-1).

Impact

Successful exploitation can result in a crash of the strongSwan IKE daemon (charon), causing a denial of service for all VPN connections managed by the affected instance. In more severe scenarios, the double-free memory corruption could be leveraged for remote code execution, potentially granting an attacker control over the VPN gateway. Given that strongSwan is commonly deployed as a perimeter VPN solution, compromise could enable network-level access to internal resources and lateral movement (Ubuntu USN-8407-1, strongSwan 6.0.7).

Exploitability

The vulnerability is remotely exploitable without authentication, as it can be triggered by sending specially crafted network traffic during IKE negotiation. As of the available information, no public proof-of-concept exploit code or in-the-wild exploitation has been confirmed, and the CVE remains in "Reserved" status in the NVD. The vulnerability has been detected by multiple commercial scanners including Nessus (plugins 319688, 320467, 321041, 321026) and Qualys (692417), indicating active scanner coverage (Feedly, Tenable Nessus). No CISA KEV listing or EPSS score is currently available for this CVE.

Exploitation steps

  1. Reconnaissance: Identify internet-facing strongSwan IKE endpoints (UDP port 500/4500) using tools like Shodan, Censys, or nmap, targeting versions 4.3.3 through 6.0.6.
  2. Craft malicious IKE packet: Construct a specially crafted IKE_SA_INIT or IKE_AUTH packet containing a malformed identity payload designed to trigger the flawed identity cloning code path in libstrongswan.
  3. Send crafted traffic: Transmit the malicious packet to the target's IKE port (UDP 500 or 4500). No prior authentication or established session is required.
  4. Trigger double-free: The malformed identity causes libstrongswan to free the same memory region twice, corrupting heap state.
  5. Achieve DoS or RCE: Depending on heap layout and exploitation precision, the result is either a daemon crash (denial of service) or, with further heap manipulation, potential arbitrary code execution as the charon process user (strongSwan 6.0.7, Ubuntu USN-8407-1).

Indicators of compromise

  • Network: Unexpected or malformed IKE packets (UDP 500/4500) from unknown sources targeting the strongSwan gateway; repeated IKE negotiation attempts with unusual identity payloads.
  • Logs: Sudden charon daemon crashes or restarts logged in /var/log/syslog or /var/log/strongswan.log; IKE error messages referencing identity parsing or memory faults.
  • Process: Unexpected termination of the charon process; core dump files generated in the strongSwan working directory (e.g., /var/run/strongswan/ or /tmp/).
  • File System: Presence of core dump files (core, charon.core) in system directories following unexplained daemon crashes.

Mitigation and workarounds

The primary remediation is to upgrade strongSwan to version 6.0.7 or later, which contains the upstream fix (strongSwan 6.0.7). Ubuntu users should update to the following patched package versions via standard system updates: Ubuntu 26.04 LTS → libstrongswan 6.0.4-1ubuntu3.1, Ubuntu 25.10 → 6.0.1-6ubuntu4.4, Ubuntu 24.04 LTS → 5.9.13-2ubuntu4.24.04.4, Ubuntu 22.04 LTS → 5.9.5-2ubuntu2.7 (Ubuntu USN-8407-1). SUSE users should apply SUSE-SU-2026:2312-1, SUSE-SU-2026:2368-1, or SUSE-SU-2026:2459-1 as applicable. As a temporary workaround where patching is not immediately possible, restrict IKE traffic (UDP 500/4500) to trusted IP ranges using firewall rules to reduce exposure.

Community reactions

The vulnerability received broad coverage across Linux distribution security channels, with Ubuntu, SUSE (multiple advisories), openSUSE, Fedora, Debian, and IPFire all issuing patches or updates within days of the upstream fix (Ubuntu USN-8407-1, SUSE Advisory). Security news outlets including SecurityOnline.info and pro-linux.de covered the vulnerability, highlighting the remote code execution potential. The IPFire project noted the fix in their Core Update 203 testing release, underscoring the broad ecosystem impact on VPN appliances (IPFire Blog).

Additional resources


SourceThis report was generated using AI

Related strongSwan vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47895HIGH7.5
  • strongSwan logostrongSwan
  • perl-vici
NoYesAug 22, 2026
CVE-2026-35334NONEN/A
  • strongSwan logostrongSwan
  • strongswan-sqlite
NoYesApr 22, 2026
CVE-2026-35333NONEN/A
  • strongSwan logostrongSwan
  • strongswan-doc
NoYesApr 22, 2026
CVE-2026-35332NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesApr 22, 2026
CVE-2026-35331NONEN/A
  • strongSwan logostrongSwan
  • strongswan-fips
NoYesApr 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management