The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel.
Security Fix(es):
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.(CVE-2025-62291)
{
"severity": "High"
}{
"aarch64": [
"strongswan-5.7.2-21.oe2003sp4.aarch64.rpm",
"strongswan-debuginfo-5.7.2-21.oe2003sp4.aarch64.rpm",
"strongswan-debugsource-5.7.2-21.oe2003sp4.aarch64.rpm"
],
"noarch": [
"strongswan-help-5.7.2-21.oe2003sp4.noarch.rpm"
],
"src": [
"strongswan-5.7.2-21.oe2003sp4.src.rpm"
],
"x86_64": [
"strongswan-5.7.2-21.oe2003sp4.x86_64.rpm",
"strongswan-debuginfo-5.7.2-21.oe2003sp4.x86_64.rpm",
"strongswan-debugsource-5.7.2-21.oe2003sp4.x86_64.rpm"
]
}