Use-After-Free Vulnerability in StrongSwan IKEv2 Rekeying
CVE-2026-78133

7.5HIGH

Key Information:

Vendor

Strongswan

Vendor
CVE Published:
11 September 2026

What is CVE-2026-78133?

A use-after-free vulnerability exists in the libcharon component of StrongSwan versions 6.0.0 through 6.0.7. This flaw arises during IKEv2 rekeying collision handling, potentially allowing an attacker to exploit the memory management flaw, which could lead to arbitrary code execution or crash the service. Users of StrongSwan are advised to update to version 6.1.0 or later to mitigate the associated risks.

Affected Version(s)

strongSwan 6.0.0 < 6.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.