Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6330-1 | strongswan security update |
Ubuntu USN |
USN-8407-1 | strongSwan vulnerability |
Sat, 22 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Double‑Free Vulnerability in Identity Parsing of StrongSwan EAP-Identity |
Sat, 22 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed. | |
| First Time appeared |
Strongswan
Strongswan strongswan |
|
| Weaknesses | CWE-415 | |
| CPEs | cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Strongswan
Strongswan strongswan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-22T22:01:26.298Z
Reserved: 2026-05-20T00:00:00.000Z
Link: CVE-2026-47895
No data.
Status : Received
Published: 2026-08-22T22:16:28.153
Modified: 2026-08-22T22:16:28.153
Link: CVE-2026-47895
No data.
OpenCVE Enrichment
Updated: 2026-08-22T23:30:07Z
Debian DSA
Ubuntu USN