logo

15-Year-Old strongSwan Flaw Lets Attackers Crash VPNs via Integer Underflow

ID: a5a368b4-5d86-54b6-af63-a7518672664f

STIX ID: report--a5a368b4-5d86-54b6-af63-a7518672664f

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A 15-year-old integer-underflow vulnerability (CVE-2026-25075) in strongSwan's EAP-TTLS plugin can be exploited to corrupt heap memory and crash the charon daemon, effectively taking VPN services offline. Bishop Fox and strongSwan disclosed the issue affecting versions 4.5.0 through 6.0.4, explained a two-step "ghost" attack that delays the visible crash, and recommended upgrading to 6.0.5+ or disabling EAP-TTLS; a safe testing tool is also available for administrators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.