openSUSE-SU-2026:20547-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20547-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20547-1
Upstream
CVE (2)
Related
Published
2026-04-16T09:06:50Z
Modified
2026-04-22T18:24:19Z
Summary
Security update for strongswan
Details

This update for strongswan fixes the following issues:

Update to strongswan 6.0.4:

  • CVE-2025-9615: NetworkManager File Access (bsc#1257359).
  • CVE-2026-25075: Integer Underflow When Handling EAP-TTLS AVP (bsc#1259472).

Changes for strongswan:

  • Fixed a vulnerability in the NetworkManager plugin that potentially allows using credentials of other local users. This vulnerability has been registered as CVE-2025-9615.
  • The maximum supported length for section names in swanctl.conf has been increased to the upper limit of 256 characters that's enforced by VICI.
  • Prevent a crash if a confused peer rekeys a Child SA twice before sending a delete.
  • Fixed a memory leak if a peer's self-signed certificate is untrusted.
References

Affected packages

openSUSE:Leap 16.0 / strongswan

Package

Name
strongswan
Purl
pkg:rpm/opensuse/strongswan&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.4-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "strongswan":  "6.0.4-160000.1.1",
            "strongswan-doc":  "6.0.4-160000.1.1",
            "strongswan-fips":  "6.0.4-160000.1.1",
            "strongswan-ipsec":  "6.0.4-160000.1.1",
            "strongswan-mysql":  "6.0.4-160000.1.1",
            "strongswan-nm":  "6.0.4-160000.1.1",
            "strongswan-sqlite":  "6.0.4-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20547-1.json"