Linuxsecurity
Multiple Vulnerabilities in strongSwan Addressed in Recent Updates
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Recent updates for strongSwan, affecting SUSE and Ubuntu systems, have addressed several critical vulnerabilities. The issues include CVE-2026-35328, which can cause an infinite loop in TLS processing, and CVE-2026-35329, leading to a null pointer dereference in PKCS#7 processing. Other vulnerabilities include integer underflows and improper certificate handling, which could allow attackers to exploit these weaknesses for denial of service or other malicious activities. The vulnerabilities affect various versions of strongSwan used in Ubuntu 26.04 LTS and SUSE systems. Security patches are available, and users are urged to update their systems promptly to mitigate risks. The updates were released on April 27 and April 28, 2026, respectively, highlighting the urgency of addressing these security flaws.
Key Points: • Multiple critical vulnerabilities in strongSwan have been patched. • Affected CVEs include CVE-2026-35328 and CVE-2026-35329. • Users of SUSE and Ubuntu 26.04 LTS are advised to update immediately.