Описание
Security update for strongswan
This update for strongswan fixes the following issues:
Update to strongswan 6.0.4:
- CVE-2025-9615: NetworkManager File Access (bsc#1257359).
- CVE-2026-25075: Integer Underflow When Handling EAP-TTLS AVP (bsc#1259472).
Changes for strongswan:
- Fixed a vulnerability in the NetworkManager plugin that potentially allows using credentials of other local users. This vulnerability has been registered as CVE-2025-9615.
- The maximum supported length for section names in swanctl.conf has been increased to the upper limit of 256 characters that's enforced by VICI.
- Prevent a crash if a confused peer rekeys a Child SA twice before sending a delete.
- Fixed a memory leak if a peer's self-signed certificate is untrusted.
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1257359
- SUSE Bug 1259472
- SUSE CVE CVE-2025-9615 page
- SUSE CVE CVE-2026-25075 page
Описание
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
Затронутые продукты
Ссылки
- CVE-2025-9615
- SUSE Bug 1257359
Описание
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
Затронутые продукты
Ссылки
- CVE-2026-25075
- SUSE Bug 1259472