
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47895 is a double-free vulnerability in strongSwan's libstrongswan library related to the incorrect cloning of certain identities, which can allow a remote attacker to cause a denial of service (crash) or potentially execute arbitrary code. The flaw affects strongSwan versions 4.3.3 and newer and was fixed in the upstream release 6.0.7 on June 8, 2026 (strongSwan 6.0.7). Ubuntu issued security notice USN-8407-1 on the same date, covering Ubuntu 22.04 LTS, 24.04 LTS, 25.10, and 26.04 LTS (Ubuntu USN-8407-1). Feedly estimates the severity as HIGH, and the CVE was discovered by Elliott Childre (Ubuntu USN-8407-1).
The root cause is a double-free memory corruption flaw (CWE-415) in libstrongswan's identity cloning logic, present since version 4.3.3. When strongSwan processes specially crafted network traffic, the flawed cloning routine can free the same memory region twice, corrupting heap state. This is exploitable remotely without authentication, as the vulnerable code path can be triggered during IKE negotiation by sending malformed identity payloads. The vulnerability was credited to researcher Elliott Childre and patched in upstream commit referenced in the 6.0.7 release (strongSwan 6.0.7, Ubuntu USN-8407-1).
Successful exploitation can result in a crash of the strongSwan IKE daemon (charon), causing a denial of service for all VPN connections managed by the affected instance. In more severe scenarios, the double-free memory corruption could be leveraged for remote code execution, potentially granting an attacker control over the VPN gateway. Given that strongSwan is commonly deployed as a perimeter VPN solution, compromise could enable network-level access to internal resources and lateral movement (Ubuntu USN-8407-1, strongSwan 6.0.7).
The vulnerability is remotely exploitable without authentication, as it can be triggered by sending specially crafted network traffic during IKE negotiation. As of the available information, no public proof-of-concept exploit code or in-the-wild exploitation has been confirmed, and the CVE remains in "Reserved" status in the NVD. The vulnerability has been detected by multiple commercial scanners including Nessus (plugins 319688, 320467, 321041, 321026) and Qualys (692417), indicating active scanner coverage (Feedly, Tenable Nessus). No CISA KEV listing or EPSS score is currently available for this CVE.
libstrongswan.libstrongswan to free the same memory region twice, corrupting heap state./var/log/syslog or /var/log/strongswan.log; IKE error messages referencing identity parsing or memory faults.charon process; core dump files generated in the strongSwan working directory (e.g., /var/run/strongswan/ or /tmp/).core, charon.core) in system directories following unexplained daemon crashes.The primary remediation is to upgrade strongSwan to version 6.0.7 or later, which contains the upstream fix (strongSwan 6.0.7). Ubuntu users should update to the following patched package versions via standard system updates: Ubuntu 26.04 LTS → libstrongswan 6.0.4-1ubuntu3.1, Ubuntu 25.10 → 6.0.1-6ubuntu4.4, Ubuntu 24.04 LTS → 5.9.13-2ubuntu4.24.04.4, Ubuntu 22.04 LTS → 5.9.5-2ubuntu2.7 (Ubuntu USN-8407-1). SUSE users should apply SUSE-SU-2026:2312-1, SUSE-SU-2026:2368-1, or SUSE-SU-2026:2459-1 as applicable. As a temporary workaround where patching is not immediately possible, restrict IKE traffic (UDP 500/4500) to trusted IP ranges using firewall rules to reduce exposure.
The vulnerability received broad coverage across Linux distribution security channels, with Ubuntu, SUSE (multiple advisories), openSUSE, Fedora, Debian, and IPFire all issuing patches or updates within days of the upstream fix (Ubuntu USN-8407-1, SUSE Advisory). Security news outlets including SecurityOnline.info and pro-linux.de covered the vulnerability, highlighting the remote code execution potential. The IPFire project noted the fix in their Core Update 203 testing release, underscoring the broad ecosystem impact on VPN appliances (IPFire Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."