The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel.
Security Fix(es):
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.(CVE-2025-62291)
{
"severity": "High"
}{
"aarch64": [
"strongswan-5.9.7-15.oe2203sp4.aarch64.rpm",
"strongswan-charon-nm-5.9.7-15.oe2203sp4.aarch64.rpm",
"strongswan-debuginfo-5.9.7-15.oe2203sp4.aarch64.rpm",
"strongswan-debugsource-5.9.7-15.oe2203sp4.aarch64.rpm",
"strongswan-libipsec-5.9.7-15.oe2203sp4.aarch64.rpm",
"strongswan-sqlite-5.9.7-15.oe2203sp4.aarch64.rpm",
"strongswan-tnc-imcvs-5.9.7-15.oe2203sp4.aarch64.rpm"
],
"src": [
"strongswan-5.9.7-15.oe2203sp4.src.rpm"
],
"x86_64": [
"strongswan-5.9.7-15.oe2203sp4.x86_64.rpm",
"strongswan-charon-nm-5.9.7-15.oe2203sp4.x86_64.rpm",
"strongswan-debuginfo-5.9.7-15.oe2203sp4.x86_64.rpm",
"strongswan-debugsource-5.9.7-15.oe2203sp4.x86_64.rpm",
"strongswan-libipsec-5.9.7-15.oe2203sp4.x86_64.rpm",
"strongswan-sqlite-5.9.7-15.oe2203sp4.x86_64.rpm",
"strongswan-tnc-imcvs-5.9.7-15.oe2203sp4.x86_64.rpm"
]
}