GHSA-55p5-7gvc-767jHighCVSS 7.5

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that...

Published
August 23, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (1)

📋 Description

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

🔗 References (4)