logo

strongSwan CVE-2026-47895: Double-Free Exploit Explained

ID: 1dd79290-e338-50f0-8386-ab17a2e01160

STIX ID: report--1dd79290-e338-50f0-8386-ab17a2e01160

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Do Son

...
...

The report describes CVE-2026-47895, a critical double-free memory corruption in strongSwan's libstrongswan component that can allow unauthenticated remote code execution when handling empty but non-NULL identity encodings; it affects versions since 4.3.3 and is fixed in strongSwan 6.0.7, with immediate patching and configuration mitigations (disable EAP/XAuth, RADIUS delegation caveats) recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.