SUSE-SU-2026:2197-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262197-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2197-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2197-1
Upstream
  • CVE-2026-35328
  • CVE-2026-35329
  • CVE-2026-35330
  • CVE-2026-35332
  • CVE-2026-35333
  • CVE-2026-35334
Related
  • CVE-2026-35328
  • CVE-2026-35329
  • CVE-2026-35330
  • CVE-2026-35332
  • CVE-2026-35333
  • CVE-2026-35334
Published
2026-06-01T07:45:02Z
Modified
2026-06-02T08:45:05Z
Summary
Security update for strongswan
Details

This update for strongswan fixes the following issues:

  • CVE-2026-35328: infinite loop when handling supported versions TLS extension (bsc#1261712).
  • CVE-2026-35329: null pointer dereference when processing padding in PKCS#7 (bsc#1261717).
  • CVE-2026-35330: integer underflow when handling EAP-SIM/AKA attributes (bsc#1261705).
  • CVE-2026-35332: null pointer dereference when handling ECDH public value in TLS (bsc#1261708).
  • CVE-2026-35333: integer underflow when handling RADIUS attributes (bsc#1261706).
  • CVE-2026-35334: null pointer dereference in RSA decryption (bsc#1261720).
References

Affected packages