SUSE-SU-2026:21203-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202621203-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21203-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:21203-1
Upstream
CVE (2)
Related
Published
2026-04-16T09:05:46Z
Modified
2026-04-22T18:26:11Z
Summary
Security update for strongswan
Details

This update for strongswan fixes the following issues:

Update to strongswan 6.0.4:

  • CVE-2025-9615: NetworkManager File Access (bsc#1257359).
  • CVE-2026-25075: Integer Underflow When Handling EAP-TTLS AVP (bsc#1259472).

Changes for strongswan:

  • Fixed a vulnerability in the NetworkManager plugin that potentially allows using credentials of other local users. This vulnerability has been registered as CVE-2025-9615.
  • The maximum supported length for section names in swanctl.conf has been increased to the upper limit of 256 characters that's enforced by VICI.
  • Prevent a crash if a confused peer rekeys a Child SA twice before sending a delete.
  • Fixed a memory leak if a peer's self-signed certificate is untrusted.
References

Affected packages

SUSE:Linux Enterprise Server 16.0 / strongswan

Package

Name
strongswan
Purl
pkg:rpm/suse/strongswan&distro=SUSE%20Linux%20Enterprise%20Server%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.4-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "strongswan":  "6.0.4-160000.1.1",
            "strongswan-doc":  "6.0.4-160000.1.1",
            "strongswan-fips":  "6.0.4-160000.1.1",
            "strongswan-ipsec":  "6.0.4-160000.1.1",
            "strongswan-mysql":  "6.0.4-160000.1.1",
            "strongswan-nm":  "6.0.4-160000.1.1",
            "strongswan-sqlite":  "6.0.4-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21203-1.json"

SUSE:Linux Enterprise Server for SAP applications 16.0 / strongswan

Package

Name
strongswan
Purl
pkg:rpm/suse/strongswan&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.4-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "strongswan":  "6.0.4-160000.1.1",
            "strongswan-doc":  "6.0.4-160000.1.1",
            "strongswan-fips":  "6.0.4-160000.1.1",
            "strongswan-ipsec":  "6.0.4-160000.1.1",
            "strongswan-mysql":  "6.0.4-160000.1.1",
            "strongswan-nm":  "6.0.4-160000.1.1",
            "strongswan-sqlite":  "6.0.4-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21203-1.json"