- Description
- In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
- Source
- cve@mitre.org
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 5.9
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- cve@mitre.org
- CWE-415
- Hype score
- Not currently trending
CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec https://t.co/iIKhATAzyJ #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin
@HugoValters
23 Aug 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A new vulnerability with increased severity was disclosed for strongSwan (CVE-2026-47895) https://t.co/YjbkvVBzGq
@vuldb
23 Aug 2026
95 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes