new file mode 100644
@@ -0,0 +1,36 @@
+From 2a3a678be189e51465d17c611982a9e5f379b016 Mon Sep 17 00:00:00 2001
+From: Tobias Brunner <tobias@strongswan.org>
+Date: Mon, 15 Jun 2026 16:02:01 +0200
+Subject: [PATCH] openssl: Fix memory leaks after enumerating certificates in
+ PKCS#7 container
+
+This can be triggered via IKEv1.
+
+Fixes: 04884be3b5f7 ("Implement openssl PKCS#7 certficiate enumeration")
+Fixes: CVE-2026-78124
+CVE: CVE-2026-78124
+Upstream-Status: Backport [https://download.strongswan.org/security/CVE-2026-78124/]
+Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com>
+
+---
+ src/libstrongswan/plugins/openssl/openssl_pkcs7.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/src/libstrongswan/plugins/openssl/openssl_pkcs7.c b/src/libstrongswan/plugins/openssl/openssl_pkcs7.c
+index 9980bf242c12..46584055ec3f 100644
+--- a/src/libstrongswan/plugins/openssl/openssl_pkcs7.c
++++ b/src/libstrongswan/plugins/openssl/openssl_pkcs7.c
+@@ -132,6 +132,10 @@ typedef struct {
+ METHOD(enumerator_t, cert_destroy, void,
+ cert_enumerator_t *this)
+ {
++ if (this->certs)
++ {
++ sk_X509_pop_free(this->certs, X509_free);
++ }
+ DESTROY_IF(this->cert);
+ free(this);
+ }
+--
+2.43.0
+
@@ -11,6 +11,7 @@ DEPENDS:append = "${@bb.utils.contains('DISTRO_FEATURES', 'tpm2', ' tpm2-tss',
SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \
file://CVE-2026-47895.patch \
file://CVE-2026-78123.patch \
+ file://CVE-2026-78124.patch \
"
SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c"
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime. Reference: [https://nvd.nist.gov/vuln/detail/cve-2026-78124] [https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html] [https://security-tracker.debian.org/tracker/CVE-2026-78124] Upstream Patch: [https://download.strongswan.org/security/CVE-2026-78124/] Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com> --- .../strongswan/CVE-2026-78124.patch | 36 +++++++++++++++++++ .../strongswan/strongswan_6.0.6.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-78124.patch