|
|
Log in / Subscribe / Register

Ubuntu alert USN-8407-1 (strongswan)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8407-1] strongSwan vulnerability
Date:  Mon, 08 Jun 2026 20:31:13 +0000
Message-ID:  <E1wWgcr-0007Mi-7i@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8407-1 June 08, 2026 strongswan vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: strongSwan could be made to crash or run programs if it received specially crafted network traffic. Software Description: - strongswan: IPsec VPN solution Details: Elliott Childre discovered that strongSwan incorrectly handled the cloning of certain identities. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libstrongswan 6.0.4-1ubuntu3.1 strongswan 6.0.4-1ubuntu3.1 Ubuntu 25.10 libstrongswan 6.0.1-6ubuntu4.4 strongswan 6.0.1-6ubuntu4.4 Ubuntu 24.04 LTS libstrongswan 5.9.13-2ubuntu4.24.04.4 strongswan 5.9.13-2ubuntu4.24.04.4 Ubuntu 22.04 LTS libstrongswan 5.9.5-2ubuntu2.7 strongswan 5.9.5-2ubuntu2.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8407-1 CVE-2026-47895 Package Information: https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ub... https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ub... https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2u... https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ub...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmonJnsACgkQcpJm3tlz hgH52g//VORnEnhhGno7pPxwDdzDql8emTPWE2KxXLPkZ4tJBsrQYc9Mxjca9+Sl jLAN2QeSMKLhg4/bup7lb73YU3PXfzBoeM18n3oiWClcvGu8xH51/0v5+9JVGhKu eMUHwuG3DP5O2wlkVIt2aAdOCVe4lzcTu3bavFfX7mKu3lwy1LZNaZV0kflvnKB9 YqfLW9zLZQ++AQJuoRdwa4xfgjBU+Y0WHOLcs/b02RO4icidZ3dXSHzha/v/9ax4 thZLgjFqW9sCyYiWWJQConuM6Eyf0f5bJNWPuUEUpoYzV1dtmA3bcumZiBIMa8xi 816fPmbW0UMLmHRM7sAoFzgCbuJYvrMPpBx5svN3J1GdFw4Z8eakkAwjBJkDJRx8 l9RBQVktlDl5ivVfYdxg8da4n45LTX4kLLrZFWL9KgfbSfQWfNBKmEf0OCAXXqf0 98TT0dkntZKmd3RjUWICI+WemyMoSufilxs5R3VzLg8pMv4pA4vA9Sr9A5b8wr8g CQKHeNpip6EGQZbJarY0DfTK8VcQ1r7p5PFSYsGFFGkrLTauWSPM8kOJ93yPLIOk aULg8VTpRKQ1CJm7mloP8Kntq36Q/jo6sU8BADhD/+oA35lAmlKzgwKDqTnepFwd 0zkLmtX5gKKtNWr7fRV4ZE6uH7eemUUxiuK2pzITlli+CgonpVw= =g9w9 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds