A high-severity flaw tracked as CVE-2026-25075 affects strongSwan versions 4.5.0 through 6.0.4 in the EAP-TTLS AVP parser. The bug stems from subtracting 8 from attacker-controlled AVP length fields without confirming the value is at least 8, creating an integer underflow that can wrap to a large unsigned value. During IKEv2 authentication, a remote unauthenticated attacker can send crafted AVP data to trigger excessive memory allocation, heap corruption, or a NULL pointer dereference, causing the charon IKE daemon to crash and resulting in denial of service.
Bishop Fox reported that exploitation may occur in one request on some systems, while others may require a second connection after heap metadata is corrupted before a segmentation fault occurs. The issue is limited to deployments that run affected strongSwan versions, have EAP-TTLS enabled, and expose the vulnerable IKEv2 code path. strongSwan disclosed the vulnerability and fixed it in version 6.0.5 by adding bounds checks, while Bishop Fox also published a non-disruptive detection approach and a GitHub test script to help identify exposed servers without crashing production systems.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-26, Bishop Fox published a technical analysis of CVE-2026-25075, including exploitation details such as possible two-phase crashing behavior on some systems. The company also released a safe detection method and GitHub test script to identify vulnerable deployments without crashing production servers.
strongSwan addressed the vulnerability in version 6.0.5 by adding bounds checking to prevent invalid AVP length handling. The fix remediates the integer underflow that could otherwise lead to excessive memory allocation, NULL dereference, or heap corruption.
On 2026-03-23, strongSwan disclosed CVE-2026-25075, an integer underflow in the EAP-TTLS AVP parser affecting versions 4.5.0 through 6.0.4. The flaw allows unauthenticated remote attackers to crash the charon IKE daemon during IKEv2 authentication, causing denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.