package/strongswan: add patch for CVE-2026-25075

This fixes the following vulnerability:
- CVE-2026-25075:
    strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow
    vulnerability in the EAP-TTLS AVP parser that allows unauthenticated
    remote attackers to cause a denial of service by sending crafted AVP
    data with invalid length fields during IKEv2 authentication. Attackers
    can exploit the failure to validate AVP length fields before
    subtraction to trigger excessive memory allocation or NULL pointer
    dereference, crashing the charon IKE daemon.
    https://www.cve.org/CVERecord?id=CVE-2026-25075

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
(cherry picked from commit cc7c20d817)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
Titouan Christophe
2026-04-21 16:33:10 +02:00
committed by Thomas Perale
parent 952d2c4fd9
commit 9eb149f742
2 changed files with 50 additions and 0 deletions

View File

@@ -0,0 +1,48 @@
From d4b3c39776f06948d875614a0eddea9561159f2a Mon Sep 17 00:00:00 2001
From: Tobias Brunner <tobias@strongswan.org>
Date: Thu, 5 Mar 2026 12:43:12 +0100
Subject: [PATCH] eap-ttls: Prevent crash if AVP length header field is invalid
The length field in the AVP header includes the 8 bytes of the header
itself. Not checking for that and later subtracting it causes an
integer underflow that usually triggers a crash when accessing a
NULL pointer that resulted from the failing chunk_alloc() call because
of the high value.
The attempted allocations for invalid lengths (0-7) are 0xfffffff8,
0xfffffffc, or 0x100000000 (0 on 32-bit hosts), so this doesn't result
in a buffer overflow even if the allocation succeeds.
Fixes: 79f2102cb442 ("implemented server side support for EAP-TTLS")
CVE: CVE-2026-25075
Upstream: https://download.strongswan.org/security/CVE-2026-25075/
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
---
src/libcharon/plugins/eap_ttls/eap_ttls_avp.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/src/libcharon/plugins/eap_ttls/eap_ttls_avp.c b/src/libcharon/plugins/eap_ttls/eap_ttls_avp.c
index 06389f7ca73e..2983bd021ded 100644
--- a/src/libcharon/plugins/eap_ttls/eap_ttls_avp.c
+++ b/src/libcharon/plugins/eap_ttls/eap_ttls_avp.c
@@ -119,7 +119,7 @@ METHOD(eap_ttls_avp_t, process, status_t,
chunk_free(&this->input);
this->inpos = 0;
- if (!success)
+ if (!success || avp_len < AVP_HEADER_LEN)
{
DBG1(DBG_IKE, "received invalid AVP header");
return FAILED;
@@ -130,7 +130,7 @@ METHOD(eap_ttls_avp_t, process, status_t,
return FAILED;
}
this->process_header = FALSE;
- this->data_len = avp_len - 8;
+ this->data_len = avp_len - AVP_HEADER_LEN;
this->input = chunk_alloc(this->data_len + (4 - avp_len) % 4);
}
--
2.43.0

View File

@@ -14,6 +14,8 @@ STRONGSWAN_DEPENDENCIES = host-pkgconf
STRONGSWAN_INSTALL_STAGING = YES
# 0001-eap_mschapv2_failure_request_len.patch
STRONGSWAN_IGNORE_CVES += CVE-2025-62291
# 0002-fix-cve-2026-25075.patch
STRONGSWAN_IGNORE_CVES += CVE-2026-25075
STRONGSWAN_CONF_OPTS += \
--without-lib-prefix \
--enable-led \