Skip to content
Ubuntu 25.10 strongSwan Critical DoS Exploit USN-8117-1 CVE-2026

Ubuntu 25.10 strongSwan Critical DoS Exploit USN-8117-1 CVE-2026

Linuxsecurity LinuxSecurity Advisories March 23, 2026

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: strongSwan could be made to consume resources or crash if it received specially crafted network traffic. Software Description: - strongswan: IPsec VPN solution Details: Kazuma Matsumoto discovered that strongSwan incorrectly handled EAP-TTLS AVPs when using the eap-ttls plugin. An attacker could possibly use this issue to cause strongSwan to consume resources and crash, resulting in a denial of service.

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: strongSwan could be made to consume resources or crash if it received specially crafted network traffic. Software Description: - strongswan: IPsec VPN solution Details: Kazuma Matsumoto discovered that strongSwan incorrectly handled EAP-TTLS AVPs when using the eap-ttls plugin. An attacker could possibly use this issue to cause strongSwan to consume resources and crash, resulting in a denial of service.

The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libstrongswan 6.0.1-6ubuntu4.2 strongswan 6.0.1-6ubuntu4.2 Ubuntu 24.04 LTS libstrongswan 5.9.13-2ubuntu4.24.04.2 strongswan 5.9.13-2ubuntu4.24.04.2 Ubuntu 22.04 LTS libstrongswan 5.9.5-2ubuntu2.5 strongswan 5.9.5-2ubuntu2.5 In general, a standard system update will make all the necessary changes.

The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libstrongswan 6.0.1-6ubuntu4.2 strongswan 6.0.1-6ubuntu4.2 Ubuntu 24.04 LTS libstrongswan 5.9.13-2ubuntu4.24.04.2 strongswan 5.9.13-2ubuntu4.24.04.2 Ubuntu 22.04 LTS libstrongswan 5.9.5-2ubuntu2.5 strongswan 5.9.5-2ubuntu2.5 In general, a standard system update will make all the necessary changes.

CVE-2026-25075

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)