Skip to main content

Share story

Security

strongSwan 6.0.5 fixes CVE-2026-25075 vulnerability

strongSwan 6.0.5 fixes CVE-2026-25075 vulnerability Image: Primary
strongSwan released version 6.0.5 to fix a vulnerability in the eap-ttls plugin. The plugin did not check the length field in the header of attribute-value pairs tunneled in EAP-TTLS. This omission could cause a 32-bit integer underflow when the parsed length value fell between 0 and 7. An unauthenticated attacker could exploit the flaw by sending a crafted message. The resulting allocation of roughly 4 GiB of memory might fail and lead to a null-pointer dereference and crash. All strongSwan versions since 4.5.0 were affected. CVE-2026-25075 was assigned to the issue. Remote code execution is not possible. Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported the bug after responsible disclosure. Clients and servers that do not use EAP-TTLS authentication are not vulnerable. Servers that terminate EAP-TTLS on a RADIUS server are also unaffected. A patch for older releases is available and applies with appropriate hunk offsets.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from strongSwan and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Infrastructure Capital
Infrastructure Capital

Nscale secures $3.36 billion in financing ahead of planned IPO

British AI data center developer Nscale said it secured $3.36 billion in convertible-note financing ahead of a planned US stock-market listing. The Third Point-led deal makes $2.36 billion available immediately, while a further $1...

Infrastructure Products
Infrastructure Products

Tower and Japan plan $4 billion optical chip expansion

Tower Semiconductor and Japan's government plan to invest a combined $4 billion in Japanese factories that make chips for optical connections, Tom's Hardware reports. Tower plans to contribute $3 billion and Japan's Ministry of Ec...

Capital AI
Capital AI

Enveda raises $311 million to advance AI-assisted drug candidates

Enveda has raised $311 million in Series E financing at a $2 billion valuation as it moves drug candidates found through its AI-assisted search of natural compounds into human testing. Catalio Capital Management led the round, wit...

Security Infrastructure
Security Infrastructure

Researchers find personal data exposed in around 16,000 Supabase databases

Security firm UpGuard found around 16,000 databases hosted by Supabase with some personal data exposed to the public web, TechCrunch reports. The accessible information included names, addresses and phone numbers; a smaller number...

Security Policy
Security Policy

CISA sets deadlines for agencies to address four exploited software flaws

CISA has added exploited vulnerabilities affecting WSO2 products, Adobe Commerce, Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities catalog. Federal agencies using the affected products must apply r...

AI Products
AI Products

S&P Global Energy opens governed data queries to customer AI agents

S&P Global Energy says it has built a way for customers' AI agents to query its structured energy data in natural language. Its domain experts organize datasets into focused Databricks Genie Agents, each with business definitions ...