[Bug 294718] security/strongswan: Update 6.0.5 -> 6.0.6 available
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294718] security/strongswan: Update 6.0.5 -> 6.0.6 available"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294718] security/strongswan: Update 6.0.5 -> 6.0.6 available"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294718] security/strongswan: Update 6.0.5 -> 6.0.6 available"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294718] security/strongswan: Update 6.0.5 -> 6.0.6 available"
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Thu, 23 Apr 2026 07:05:12 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294718
Bug ID: 294718
Summary: security/strongswan: Update 6.0.5 -> 6.0.6 available
Product: Ports & Packages
Version: Latest
Hardware: Any
OS: Any
Status: New
Severity: Affects Only Me
Priority: ---
Component: Individual Port(s)
Assignee: ports-bugs@FreeBSD.org
Reporter: mike@bressem.com
CC: strongswan@Nanoteq.com
Flags: maintainer-feedback?(strongswan@Nanoteq.com)
CC: strongswan@Nanoteq.com
Vulnerabilities
CVE-2026-35328 - Fixed a vulnerability in libtls related to the processing of
the supported_versions extension in TLS that can result in an infinite loop.
Affects 5.9.2 and newer.
CVE-2026-35329 - Fixed a vulnerability in libstrongswan and the pkcs7 plugin
related to the processing of encrypted PKCS#7 containers that can result in a
crash. Affects 5.0.2 and newer.
CVE-2026-35330 - Fixed a vulnerability in libsimaka related to the processing
of certain EAP-SIM/AKA attributes that can result in an infinite loop or a
heap-based buffer overflow and potentially remote code execution. Affects 4.3.6
and newer.
CVE-2026-35331 - Fixed a vulnerability in the constraints plugin related to the
processing of X.509 name constraints that can allow authentication with
certificates that violate the constraints. Affects 4.5.1 and newer.
CVE-2026-35332 - Fixed a vulnerability in libtls related to the processing of
ECDH public values in TLS < 1.3 that can result in a crash. Affects 4.5.0 and
newer.
CVE-2026-35333 - Fixed a vulnerability in libradius related to the processing
of RADIUS attributes that can result in an infinite loop or an out-of-bounds
read that may cause a crash. Affects 4.2.14 and newer.
CVE-2026-35334 - Fixed a vulnerability in the gmp plugin related to RSA
decryption that can result in a crash. Affects 4.3.2 and newer.
--
You are receiving this mail because:
You are the assignee for the bug.