Skip to content
Critical strongSwan Vulnerability Exposes Multiple Ubuntu Versions to DoS and Code Execution

Critical strongSwan Vulnerability Exposes Multiple Ubuntu Versions to DoS and Code Execution

First seen 9 Jun 2026, 02:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 10, 2026 at 02:29 UTC
  • strongSwan vulnerability allows remote DoS and potential code execution.
  • Affected Ubuntu versions include 26.04 LTS, 25.10, 24.04 LTS, and 22.04 LTS.
  • Users should update to the latest package versions to mitigate risks.

A vulnerability in strongSwan, discovered by Elliott Childre, affects multiple Ubuntu releases, including 26.04 LTS, 25.10, 24.04 LTS, and 22.04 LTS. The flaw allows remote attackers to exploit specially crafted network traffic to crash the service or potentially execute arbitrary code. Users are urged to update their systems to the latest package versions to mitigate the risk. The vulnerability is categorized as a denial of service (DoS) risk, impacting the IPsec VPN solution strongSwan. A standard system update will address the issue across the affected versions. The vulnerability has not been linked to any known active exploitation at this time. The affected package versions include strongswan 6.0.4-1ubuntu3.1 for 26.04 LTS and earlier versions for other releases.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2026-06-08
strongSwan vulnerability disclosed
Elliott Childre reported a flaw in strongSwan that could lead to crashes or code execution via crafted network traffic.
Ubuntu
2026-06-09
Linuxsecurity reports on vulnerability
Linuxsecurity published details on the strongSwan vulnerability affecting multiple Ubuntu versions, urging updates.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed