Linuxsecurity Critical DoS Vulnerability in strongSwan Affects Multiple Ubuntu Releases
Article Content
- •CVE-2026-25075 affects Ubuntu 25.10, 24.04 LTS, and 22.04 LTS.
- •The vulnerability allows denial of service via specially crafted network traffic.
- •Users should update to the latest strongSwan package versions to mitigate the risk.
A critical vulnerability in strongSwan, identified as CVE-2026-25075, has been discovered, affecting Ubuntu 25.10, 24.04 LTS, and 22.04 LTS. The flaw, found by Kazuma Matsumoto, allows attackers to send specially crafted network traffic that can cause strongSwan to consume excessive resources or crash, resulting in a denial of service. The vulnerability arises from improper handling of EAP-TTLS AVPs in the eap-ttls plugin. Users are advised to update their systems to the latest package versions to mitigate the risk. The problem can be resolved through a standard system update. The vulnerability was published on March 23, 2026. No active exploitation has been reported yet, but the potential for denial of service poses a significant risk to affected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2026-25075 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…