LOW 3.7 NVD
CVE-2026-78124
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetim
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
Remediation
$ sudo apt install --only-upgrade strongswanReferences
- https://github.com/strongswan/strongswan/releases/tag/6.1.0
- https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html
This low severity vulnerability with a CVSS score of 3.7 was published on 2026-09-11 via NVD. A remediation command is available below.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.