mbox series

[meta-networking,wrynose,00/11] strongswan: fix

Message ID 20261001120417.1280843-1-Abhishek.Bachiphale@windriver.com
Headers show
Series strongswan: fix | expand

Message

Abhishek Bachiphale Oct. 1, 2026, 12:04 p.m. UTC
This series backports the September 2026 strongSwan security fixes to
the 6.0.6 recipe in meta-networking. All patches are taken from the official
strongSwan security advisory archive at download.strongswan.org/security/,
version-banded for 6.0.x, and all are fixed upstream in strongSwan
6.1.0.

CVE-2026-47895 is already applied on this branch and is not included
here.

    CVE-2026-78123  openssl plugin PKCS#7 expired pointer dereference
    CVE-2026-78124  openssl plugin PKCS#7 certificate memory leak
    CVE-2026-78126  eap-aka NULL deref on AKA-Synchronization-Failure
    CVE-2026-78127  libcharon IKE message logging memory exhaustion
    CVE-2026-78129  libstrongswan encrypted PKCS#7 DoS
    CVE-2026-78130  x509 attribute certificate verification DoS
    CVE-2026-78131  x509 attribute certificate identity parsing DoS
    CVE-2026-78132  x509 ietfAttrSyntax ASN.1 parsing DoS
    CVE-2026-78133  libcharon IKEv2 rekey-collision use-after-free
    CVE-2026-78134  eap-peap/eap-ttls inner auth propagation / authz bypass
    CVE-2026-78135  libcharon early CREATE_CHILD_SA auth bypass


Abhishek Bachiphale (11):
  strongswan: fix CVE-2026-78123
  strongswan: fix CVE-2026-78124
  strongswan: fix CVE-2026-78126
  strongswan: fix CVE-2026-78127
  strongswan: fix CVE-2026-78129
  strongswan: fix CVE-2026-78130
  strongswan: fix CVE-2026-78131
  strongswan: fix CVE-2026-78132
  strongswan: fix CVE-2026-78133
  strongswan: fix CVE-2026-78134
  strongswan: fix CVE-2026-78135

 .../strongswan/CVE-2026-78123.patch           |  53 ++
 .../strongswan/CVE-2026-78124.patch           |  36 +
 .../strongswan/CVE-2026-78126.patch           |  39 +
 .../strongswan/CVE-2026-78127.patch           | 117 +++
 .../strongswan/CVE-2026-78129.patch           | 157 ++++
 .../strongswan/CVE-2026-78130.patch           |  51 ++
 .../strongswan/CVE-2026-78131.patch           |  85 +++
 .../strongswan/CVE-2026-78132.patch           |  77 ++
 .../strongswan/CVE-2026-78133.patch           | 622 +++++++++++++++
 .../strongswan/CVE-2026-78134.patch           | 711 ++++++++++++++++++
 .../strongswan/CVE-2026-78135.patch           |  74 ++
 .../strongswan/strongswan_6.0.6.bb            |  13 +-
 12 files changed, 2034 insertions(+), 1 deletion(-)
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78123.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78124.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78126.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78127.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78129.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78130.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78131.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78132.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78133.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78134.patch
 create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78135.patch