In strongSwan before 6.0.7, identity parsing/cloning is...
High severity
Unreviewed
Published
Aug 23, 2026
to the GitHub Advisory Database
•
Updated Aug 23, 2026
Description
Published by the National Vulnerability Database
Aug 22, 2026
Published to the GitHub Advisory Database
Aug 23, 2026
Last updated
Aug 23, 2026
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
References