USN-8789-1: strongSwan vulnerabilities
Cosa significa
Ubuntu ha rilasciato un avviso di sicurezza (USN-8789-1) riguardante vulnerabilità in strongSwan, un'implementazione IPsec VPN. Le vulnerabilità permettono a un attaccante remoto di causare un denial of service o ottenere informazioni sensibili. Le patch sono disponibili per diverse versioni di strongSwan.
Perché conta
Per le PMI italiane, queste vulnerabilità possono compromettere la disponibilità e la riservatezza dei dati, specialmente se strongSwan è utilizzato per la gestione di connessioni sicure. L'aggiornamento delle versioni è fondamentale per mitigare i rischi.
Azioni consigliate
- Applicare le patch disponibili per strongSwan (6.0.4-1ubuntu3.2, 5.9.13-2ubuntu4.24.04.5, 5.9.5-2ubuntu2.8)
- Verificare l'aggiornamento di tutti i sistemi Ubuntu 26.04 LTS
- Monitorare i log di strongSwan per errori di memoria o crash
- Implementare controlli di accesso per prevenire accessi non autorizzati
- Eseguire un backup regolare dei dati sensibili
- Configurare regole di firewall per limitare l'accesso alle porte utilizzate da strongSwan
Sistemi e prodotti interessati
- strongswan < 6.0.4-1ubuntu3.2
- strongswan < 5.9.13-2ubuntu4.24.04.5
- strongswan < 5.9.5-2ubuntu2.8
Cosa cercare (rilevamento)
- Ricerca di errori di memoria durante l'elenco di certificati in PKCS#7
- Monitoraggio di crash improvvisi di strongSwan
- Analisi di richieste di decrittografia PKCS#5 anomale
- Verifica di errori durante la gestione di certificati con issuer name mancante
- Controllo di accessi non autorizzati a certificati X.509
- Analisi di richieste CREATE_CHILD_SA non valide
Estratto della fonte usato dal modello
Your submission was sent successfully! Close Thank you for contacting us. A member of our team will be in touch shortly. Close You have successfully unsubscribed! Close Thank you for signing up for our newsletter! In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team. Close Your preferences have been successfully updated. Close notification Please try again or file a bug report. Close USN-8789-1: strongSwan vulnerabilities Several security issues were fixed in strongSwan. strongswan - IPsec VPN solution It was discovered that strongSwan incorrectly handled PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. ( CVE-2026-78123 ) It was discovered that strongSwan incorrectly handled memory when enumerating certificates in PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to obtain sensitive information. ( CVE-2026-78124 ) It was discovered that strongSwan incorrectly handled AKA-Synchronization-Failure messages in the eap-aka plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. ( CVE-2026-78126 ) It was discovered that strongSwan incorrectly handled memory when stringifying IKE messages. A remote attacker... It was discovered that strongSwan incorrectly handled PKCS#7 containers in the openssl plugin. A remote att
Benefici operativi potenziali
- Riduzione della superficie esposta
- Miglioramento della disponibilità dei servizi
- Protezione dei dati sensibili
- Riduzione del rischio di attacchi di DoS
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
It was discovered that strongSwan incorrectly handled PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2026-78123) It was discovered that strongSwan incorrectly handled memory when enumerating certificates in PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-78124) It was discovered that strongSwan incorrectly handled AKA-Synchronization-Failure messages in the eap-aka plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2026-78126) It was discovered that strongSwan incorrectly handled memory when stringifying IKE messages. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-78127) It was discovered that strongSwan incorrectly handled PKCS#5 decryption. A remote attacker could possibly use this issue to cause strongSwan to consume excessive resources, leading to a denial of service. (CVE-2026-78129) It was discovered that strongSwan incorrectly handled attribute certificates in the x509 plugin when the issuer name was missing. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2026-78130) It was discovered that strongSwan incorrectly handled memory when parsing attribute certificates in the x509 plugin. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-78131) It was discovered that strongSwan incorrectly handled attribute certificates containing ietfAttrSyntax values in the x509 plugin. A remote attacker could possibly use this issue to cause strongSwan to consume exce
- Fonte
- Ubuntu Security Notices
- Entità pubblicatrice
- Ubuntu Security
- Tipo entità
- vendor security
- Area
- Global
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 21/09/2026 14:16
- MITRE ATT&CK
- T1562, T1486
- CVE
- CVE-2026-78123, CVE-2026-78124, CVE-2026-78126, CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.