CVE-2026-25075
strongswan - security update
EPSS 1.0%
描述
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
如何修補 CVE-2026-25075
要修補 CVE-2026-25075,請將受影響套件升級到下列已修補版本。
- Debian/strongswan—升級至 5.9.1-1+deb11u6 或更新版本
- —升級至 5.9.1-1+deb11u6 或更新版本
- —升級至 5.9.8-5+deb12u3 或更新版本
CVE-2026-25075 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 5.9.1-1+deb11u6
- from 0, < 5.9.1-1+deb11u6
- from 0, < 5.9.8-5+deb12u3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |