Skip to content

[Deepin Integration]~[v25-Release] feat: update strongswan to 6.0.1-6+deb13u7 by deepin-community-bot[bot]@deepin-community/strongswan by deepin-community-ci-bot[bot] #14046

Description

@deepin-bot

Package information | 软件包信息

包名 版本
strongswan 6.0.1-6+deb13u7

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-4599/testing/ ./

Changelog | 更新信息

strongswan (6.0.1-6+deb13u7) trixie-security; urgency=medium

  • d/patches: add fix for undefined memory access when verifying PKCS#7
    containers (CVE-2026-78123)
  • d/patches: add patch to fix memory leaks after enumerating certificates in
    PKCS#7 containers (CVE-2026-78124)
  • d/patches: fix NULL-pointer dereference in EAP-AKA (CVE-2026-78126)
  • d/patches: avoid memory leak in IKE message logging (CVE-2026-78127)
  • d/patches: fix potential DoS by validating PKCS#5 parsed parameters
    (CVE-2026-78129)
  • d/patches: fix NULL-pointer dereference in x509 code (CVE-2026-78130)
  • d/patches: fix memory leak when parsing x509 attribute certificates
    (CVE-2026-78131)
  • d/patches: fix infinite loop when parsing x509 attribute certificates
    (CVE-2026-78132)
  • d/patches: fix use-after-free in IKEv2 rekeying (CVE-2026-78133)
  • d/patches: fix several issues with binding identities to the IKE SA
    (CVE-2026-78134)
  • d/patches: properly reject CREATE_CHILD_SA requests on unestablished
    IKE_SA (CVE-2026-78135)

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions