strongSwan vulnerability
Published: Mon, 08 Jun 2026 17:28
Summary
strongSwan could be made to crash or run programs if it received specially crafted network traffic.
Details
Elliott Childre discovered that strongSwan incorrectly handled the cloning of certain identities. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service, or possibly execute arbitrary code.
Recommended actions per Ubuntu release
StackPatch playbook auto-generated per release codename and per affected package.
Ubuntu jammy
strongswan→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
charon-cmd→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y charon-cmd
Most apt upgrades restart their service automatically. needrestart lists anything else.
charon-systemd→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y charon-systemd
Most apt upgrades restart their service automatically. needrestart lists anything else.
libcharon-extauth-plugins→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libcharon-extauth-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libcharon-extra-plugins→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libcharon-extra-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan-extra-plugins→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan-extra-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan-standard-plugins→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan-standard-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-charon→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-charon
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-libcharon→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-libcharon
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-nm→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-nm
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-pki→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-pki
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-scepclient→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-scepclient
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-starter→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-starter
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-swanctl→5.9.5-2ubuntu2.7apt_upgradeStandard apt upgrade. Install 5.9.5-2ubuntu2.7 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-swanctl
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu noble
strongswan→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
charon-cmd→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y charon-cmd
Most apt upgrades restart their service automatically. needrestart lists anything else.
charon-systemd→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y charon-systemd
Most apt upgrades restart their service automatically. needrestart lists anything else.
libcharon-extauth-plugins→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libcharon-extauth-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libcharon-extra-plugins→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libcharon-extra-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan-extra-plugins→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan-extra-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan-standard-plugins→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan-standard-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-charon→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-charon
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-libcharon→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-libcharon
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-nm→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-nm
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-pki→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-pki
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-starter→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-starter
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-swanctl→5.9.13-2ubuntu4.24.04.4apt_upgradeStandard apt upgrade. Install 5.9.13-2ubuntu4.24.04.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-swanctl
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu questing
strongswan→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
charon-cmd→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y charon-cmd
Most apt upgrades restart their service automatically. needrestart lists anything else.
charon-systemd→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y charon-systemd
Most apt upgrades restart their service automatically. needrestart lists anything else.
libcharon-extauth-plugins→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libcharon-extauth-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libcharon-extra-plugins→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libcharon-extra-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan-extra-plugins→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan-extra-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan-standard-plugins→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan-standard-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-charon→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-charon
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-libcharon→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-libcharon
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-nm→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-nm
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-pki→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-pki
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-starter→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-starter
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-swanctl→6.0.1-6ubuntu4.4apt_upgradeStandard apt upgrade. Install 6.0.1-6ubuntu4.4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-swanctl
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu resolute
strongswan→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
charon-cmd→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y charon-cmd
Most apt upgrades restart their service automatically. needrestart lists anything else.
charon-systemd→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y charon-systemd
Most apt upgrades restart their service automatically. needrestart lists anything else.
libcharon-extauth-plugins→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libcharon-extauth-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libcharon-extra-plugins→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libcharon-extra-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan-extra-plugins→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan-extra-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
libstrongswan-standard-plugins→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libstrongswan-standard-plugins
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-charon→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-charon
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-libcharon→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-libcharon
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-nm→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-nm
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-pki→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-pki
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-starter→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-starter
Most apt upgrades restart their service automatically. needrestart lists anything else.
strongswan-swanctl→6.0.4-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 6.0.4-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y strongswan-swanctl
Most apt upgrades restart their service automatically. needrestart lists anything else.
Are YOU affected by USN-8407-1?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8407-1 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
StackPatch runs this match against YOUR installed packages every hour
Free 1-server / $99 lifetime founder seat (50 only) / $19+/mo monthly. Indie pricing.