USN-8789-1

Source
https://ubuntu.com/security/notices/USN-8789-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8789-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8789-1
Upstream
CVE (11)
Related
Published
2026-09-21T12:16:30Z
Modified
2026-09-21T21:42:46Z
Summary
strongswan vulnerabilities
Details

It was discovered that strongSwan incorrectly handled PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2026-78123)

It was discovered that strongSwan incorrectly handled memory when enumerating certificates in PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-78124)

It was discovered that strongSwan incorrectly handled AKA-Synchronization-Failure messages in the eap-aka plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2026-78126)

It was discovered that strongSwan incorrectly handled memory when stringifying IKE messages. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-78127)

It was discovered that strongSwan incorrectly handled PKCS#5 decryption. A remote attacker could possibly use this issue to cause strongSwan to consume excessive resources, leading to a denial of service. (CVE-2026-78129)

It was discovered that strongSwan incorrectly handled attribute certificates in the x509 plugin when the issuer name was missing. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2026-78130)

It was discovered that strongSwan incorrectly handled memory when parsing attribute certificates in the x509 plugin. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-78131)

It was discovered that strongSwan incorrectly handled attribute certificates containing ietfAttrSyntax values in the x509 plugin. A remote attacker could possibly use this issue to cause strongSwan to consume excessive resources, leading to a denial of service. (CVE-2026-78132)

It was discovered that strongSwan incorrectly handled IKEv2 rekeying collisions with multi-key exchange. A remote attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-78133)

It was discovered that strongSwan incorrectly validated inner EAP method authentication details in the eap-ttls and eap-peap plugins. An authenticated user could possibly use this issue to bypass authentication. (CVE-2026-78134)

It was discovered that strongSwan incorrectly handled CREATE_CHILD_SA requests on unestablished IKE_SAs. A remote attacker could possibly use this issue to bypass authentication. (CVE-2026-78135)

References

Affected packages

Ubuntu:22.04:LTS / strongswan

Package

Name
strongswan
Purl
pkg:deb/ubuntu/strongswan?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.9.5-2ubuntu2.8

Affected versions

5.*
5.9.1-1ubuntu3
5.9.1-1ubuntu3.1
5.9.4-1ubuntu1
5.9.4-1ubuntu2
5.9.4-1ubuntu3
5.9.4-1ubuntu4
5.9.5-2ubuntu1
5.9.5-2ubuntu2
5.9.5-2ubuntu2.1
5.9.5-2ubuntu2.2
5.9.5-2ubuntu2.3
5.9.5-2ubuntu2.4
5.9.5-2ubuntu2.5
5.9.5-2ubuntu2.6
5.9.5-2ubuntu2.7

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "charon-cmd",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "charon-systemd",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "libcharon-extauth-plugins",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "libcharon-extra-plugins",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "libstrongswan",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "libstrongswan-extra-plugins",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "libstrongswan-standard-plugins",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "strongswan",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "strongswan-charon",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "strongswan-libcharon",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "strongswan-nm",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "strongswan-pki",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "strongswan-scepclient",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "strongswan-starter",
            "binary_version":  "5.9.5-2ubuntu2.8"
        },
        {
            "binary_name":  "strongswan-swanctl",
            "binary_version":  "5.9.5-2ubuntu2.8"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-78123",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78124",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78126",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78127",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78129",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78130",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78131",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78132",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78134",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78135",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:22.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8789-1.json"

Ubuntu:24.04:LTS / strongswan

Package

Name
strongswan
Purl
pkg:deb/ubuntu/strongswan?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.9.13-2ubuntu4.24.04.5

Affected versions

5.*
5.9.11-1ubuntu1
5.9.11-1ubuntu2
5.9.12-1ubuntu1
5.9.13-2ubuntu1
5.9.13-2ubuntu3
5.9.13-2ubuntu4
5.9.13-2ubuntu4.24.04.1
5.9.13-2ubuntu4.24.04.2
5.9.13-2ubuntu4.24.04.3
5.9.13-2ubuntu4.24.04.4

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "charon-cmd",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "charon-systemd",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "libcharon-extauth-plugins",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "libcharon-extra-plugins",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "libstrongswan",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "libstrongswan-extra-plugins",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "libstrongswan-standard-plugins",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "strongswan",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "strongswan-charon",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "strongswan-libcharon",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "strongswan-nm",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "strongswan-pki",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "strongswan-starter",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        },
        {
            "binary_name":  "strongswan-swanctl",
            "binary_version":  "5.9.13-2ubuntu4.24.04.5"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-78123",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78124",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78126",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78127",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78129",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78130",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78131",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78132",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78134",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78135",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8789-1.json"

Ubuntu:26.04:LTS / strongswan

Package

Name
strongswan
Purl
pkg:deb/ubuntu/strongswan?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.4-1ubuntu3.2

Affected versions

6.*
6.0.1-6ubuntu4
6.0.1-6ubuntu5
6.0.4-1ubuntu1
6.0.4-1ubuntu2
6.0.4-1ubuntu3
6.0.4-1ubuntu3.1

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "charon-cmd",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "charon-systemd",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "libcharon-extauth-plugins",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "libcharon-extra-plugins",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "libstrongswan",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "libstrongswan-extra-plugins",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "libstrongswan-standard-plugins",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "strongswan",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "strongswan-charon",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "strongswan-libcharon",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "strongswan-nm",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "strongswan-pki",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "strongswan-starter",
            "binary_version":  "6.0.4-1ubuntu3.2"
        },
        {
            "binary_name":  "strongswan-swanctl",
            "binary_version":  "6.0.4-1ubuntu3.2"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-78123",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78124",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78126",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78127",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78129",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78130",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78131",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78132",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78133",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78134",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-78135",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:26.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8789-1.json"