Debian dsa-6487 : charon-cmd - security update

high Nessus Plugin ID 343484

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6487 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6487-1 [email protected] https://www.debian.org/security/ Yves-Alexis Perez September 06, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : strongswan CVE ID : CVE-2026-78123 CVE-2026-78124 CVE-2026-78126 CVE-2026-78127 CVE-2026-78129 CVE-2026-78130 CVE-2026-78131 CVE-2026-78132 CVE-2026-78133 CVE-2026-78134 CVE-2026-78135

Multiple vulnerabilities were found in strongSwan, an IKE/IPsec suite.

CVE-2026-78123

An undefined memory access vulnerability in the openssl plugin when handling PKCS#7 containers, that can result in a crash.

CVE-2026-78124

A memory leak in the openssl plugin during the enumeration of certificates in PKCS#7 containers.

CVE-2026-78126

A NULL-pointer dereference vulnerability in the eap-aka plugin when processing an unexpected AKA-Synchronization-Failure message, that can result in a crash.

CVE-2026-78127

Memory leak in libcharon message stringification during the logging of IKE messages, that can result in a denial of service via memory exhaustion.

CVE-2026-78129

An unbounded iteration in libstrongswan when decrypting encrypted PKCS#7 containers, that can result in a denial of service.

CVE-2026-78130

A NULL-Pointer dereference vulnerability in the x509 plugin during the verification of X.509 attribute certificates, that can lead to a denial of service.

CVE-2026-78131

A memory leak in the x509 plugin during the parsing of identities in X.509 attribute certificates, that can lead to a denial of service.

CVE-2026-78132

An infinite loop vulnerability in the x509 plugin when parsing the ietfAttrSyntax ASN.1 type in X.509 attribute certificates, that can lead to a denial of service.

CVE-2026-78133

A vulnerability in libcharon when handling IKEv2 rekeying collisions, that can result in a use-after-free and potentially remote code execution.

CVE-2026-78134

A vulnerability in the eap-peap and eap-ttls plugins in the propagation of authentication details from inner EAP methods. Missing Inner EAP authentication details can result in incorrect identity binding and potential authorization bypass.

CVE-2026-78135

A vulnerability in libcharon when handling CREATE_CHILD_SA requests on unestablished IKE SAs strongSwan, that can result in the creation of a usable Child SA before authentication completes.

For the stable distribution (trixie), these problems have been fixed in version 6.0.1-6+deb13u7.

We recommend that you upgrade your strongswan packages.

For the detailed security status of strongswan please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/strongswan

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the charon-cmd packages.

See Also

https://packages.debian.org/source/trixie/strongswan

https://security-tracker.debian.org/tracker/CVE-2026-78123

https://security-tracker.debian.org/tracker/CVE-2026-78124

https://security-tracker.debian.org/tracker/CVE-2026-78126

https://security-tracker.debian.org/tracker/CVE-2026-78127

https://security-tracker.debian.org/tracker/CVE-2026-78129

https://security-tracker.debian.org/tracker/CVE-2026-78130

https://security-tracker.debian.org/tracker/CVE-2026-78131

https://security-tracker.debian.org/tracker/CVE-2026-78132

https://security-tracker.debian.org/tracker/CVE-2026-78133

https://security-tracker.debian.org/tracker/CVE-2026-78134

https://security-tracker.debian.org/tracker/CVE-2026-78135

https://security-tracker.debian.org/tracker/source-package/strongswan

Plugin Details

Severity: High

ID: 343484

File Name: debian_DSA-6487.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/7/2026

Updated: 9/7/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-78135

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:charon-cmd, p-cpe:/a:debian:debian_linux:charon-systemd, p-cpe:/a:debian:debian_linux:libcharon-extauth-plugins, p-cpe:/a:debian:debian_linux:libcharon-extra-plugins, p-cpe:/a:debian:debian_linux:libstrongswan-extra-plugins, p-cpe:/a:debian:debian_linux:libstrongswan-standard-plugins, p-cpe:/a:debian:debian_linux:libstrongswan, p-cpe:/a:debian:debian_linux:strongswan-charon, p-cpe:/a:debian:debian_linux:strongswan-libcharon, p-cpe:/a:debian:debian_linux:strongswan-nm, p-cpe:/a:debian:debian_linux:strongswan-pki, p-cpe:/a:debian:debian_linux:strongswan-starter, p-cpe:/a:debian:debian_linux:strongswan-swanctl, p-cpe:/a:debian:debian_linux:strongswan

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 9/6/2026

Vulnerability Publication Date: 9/6/2026

Reference Information

CVE: CVE-2026-78123, CVE-2026-78124, CVE-2026-78126, CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134, CVE-2026-78135