CVE-2026-47895
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strongSwan | strongSwan | 4..3.3 < 6.0.7 | affected |
Weaknesses
- CWE-415: CWE-415 Double Free
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.