CVE-2026-78133
strongSwan vulnerability analysis and mitigation

Overview

CVE-2026-78133 is a use-after-free vulnerability in strongSwan's libcharon library, triggered during IKEv2 rekeying collision handling, which can potentially lead to remote code execution. The CVE was reserved and first indexed by Feedly on September 7, 2026, with a Debian security advisory published shortly after. Affected software is strongSwan (vendor: strongswan), though specific version ranges have not yet been publicly detailed. The estimated CVSS severity is Medium (Feedly, Debian Advisory).

Technical details

The root cause is a use-after-free condition (CWE-416) in libcharon, the core IKE daemon library in strongSwan, occurring when two IKEv2 rekeying operations collide — a known edge case in the IKEv2 protocol where both peers simultaneously initiate rekeying of the same SA. This race condition can cause a memory object to be freed and subsequently accessed, potentially allowing an attacker to corrupt heap memory. Exploitation would require the ability to participate in or influence IKEv2 session rekeying, which may be achievable by a network-adjacent or remote attacker depending on the deployment. Nessus detection plugins 343484 and 343509 have been published to identify vulnerable systems (Feedly, Tenable Plugin 343484, Tenable Plugin 343509).

Impact

Successful exploitation of this use-after-free vulnerability could allow a remote attacker to execute arbitrary code in the context of the strongSwan IKE daemon, which typically runs with elevated privileges. This could result in full compromise of the VPN gateway, enabling interception or manipulation of VPN traffic, lateral movement into protected network segments, and potential exposure of sensitive credentials or data traversing the VPN tunnel. Availability impact is also significant, as exploitation may crash the IKE daemon, disrupting VPN connectivity (Feedly, Debian Advisory).

Exploitability

As of the time of this report, no public proof-of-concept exploit code has been identified, and there is no confirmed evidence of in-the-wild exploitation (Feedly). The CVE status remains "Reserved" with limited published technical detail, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS score data is not yet available. The vulnerability's exploitability is constrained by the requirement to trigger an IKEv2 rekeying collision, which may require a man-in-the-middle position or control over a peer VPN endpoint.

Mitigation and workarounds

Users should apply the patches distributed via the Debian security advisory (DSA) for strongSwan as soon as possible, upgrading to the fixed package version referenced in the advisory (Debian Advisory). Organizations running strongSwan on other Linux distributions should monitor their respective vendor channels for updated packages. As a temporary workaround, consider restricting IKEv2 rekeying intervals or disabling rekeying where operationally feasible, and limit exposure of IKE endpoints to trusted peers only. Use Nessus plugins 343484 and 343509 to scan for vulnerable instances (Tenable Plugin 343484, Tenable Plugin 343509).

Community reactions

The vulnerability received coverage in the German Linux security community via Pro-Linux.de, which reported on multiple strongSwan issues (Pro-Linux). AusCERT published a bulletin (ESB-2026.10585) alerting its constituency (AusCERT). LinuxCompatible.org included it in a daily security roundup covering patches across major distributions (LinuxCompatible). No notable individual researcher commentary or significant social media discussion has been identified at this time.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

strongswan

Fixed

sid

strongswan: 6.1.0-1

Fixed

trixie

strongswan: 6.0.1-6+deb13u7

Fixed

Ubuntu

Affected

bionic (esm-infra)

strongswan

Not Affected

bionic (fips-updates)

strongswan

Not Affected

bionic (fips)

strongswan

Not Affected

devel

strongswan: 6.0.7-1ubuntu3

Affected

focal (esm-infra)

strongswan

Not Affected

focal (fips-updates)

strongswan

Not Affected

focal (fips)

strongswan

Not Affected

jammy

strongswan

Not Affected

SourceThis report was generated using AI

Related strongSwan vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78135NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026
CVE-2026-78134NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026
CVE-2026-78133NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026
CVE-2026-78132NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026
CVE-2026-78131NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management