Debian Package Tracker
Register | Log in
Subscribe

strongswan

IPsec VPN solution metapackage

Choose email to subscribe with

general
  • source: strongswan (main)
  • version: 6.1.0-2
  • maintainer: strongSwan Maintainers (archive) (DMD)
  • uploaders: Yves-Alexis Perez [DMD]
  • arch: all any
  • std-ver: 4.7.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.9.1-1+deb11u4
  • o-o-sec: 5.9.1-1+deb11u6
  • oldstable: 5.9.8-5+deb12u5
  • old-sec: 5.9.8-5+deb12u5
  • old-p-u: 5.9.8-5+deb12u5
  • stable: 6.0.1-6+deb13u6
  • stable-sec: 6.0.1-6+deb13u7
  • stable-p-u: 6.0.1-6+deb13u7
  • testing: 6.0.7-1
  • unstable: 6.1.0-2
versioned links
  • 5.9.1-1+deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.9.1-1+deb11u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.9.8-5+deb12u5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.1-6+deb13u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.1-6+deb13u7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.7-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.1.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • charon-cmd
  • charon-systemd (1 bugs: 0, 1, 0, 0)
  • libcharon-extauth-plugins
  • libcharon-extra-plugins (5 bugs: 0, 3, 2, 0)
  • libstrongswan (1 bugs: 0, 1, 0, 0)
  • libstrongswan-extra-plugins
  • libstrongswan-standard-plugins (1 bugs: 0, 1, 0, 0)
  • strongswan (11 bugs: 0, 8, 3, 0)
  • strongswan-charon (2 bugs: 0, 1, 1, 0)
  • strongswan-libcharon
  • strongswan-nm (4 bugs: 0, 4, 0, 0)
  • strongswan-pki (1 bugs: 0, 0, 1, 0)
  • strongswan-starter (5 bugs: 0, 2, 3, 0)
  • strongswan-swanctl (2 bugs: 0, 2, 0, 0)
action needed
11 security issues in forky high

There are 11 open security issues in forky.

11 important issues:
  • CVE-2026-78123: strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
  • CVE-2026-78124: strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
  • CVE-2026-78126: strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
  • CVE-2026-78127: libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
  • CVE-2026-78129: strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
  • CVE-2026-78130: strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
  • CVE-2026-78131: strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
  • CVE-2026-78132: strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.
  • CVE-2026-78133: libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.
  • CVE-2026-78134: strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
  • CVE-2026-78135: libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
Created: 2026-09-07 Last update: 2026-09-11 06:02
10 security issues in bookworm high

There are 10 open security issues in bookworm.

10 important issues:
  • CVE-2026-78123: strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
  • CVE-2026-78124: strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
  • CVE-2026-78126: strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
  • CVE-2026-78127: libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
  • CVE-2026-78129: strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
  • CVE-2026-78130: strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
  • CVE-2026-78131: strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
  • CVE-2026-78132: strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.
  • CVE-2026-78134: strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
  • CVE-2026-78135: libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
Created: 2026-09-07 Last update: 2026-09-11 06:02
8 security issues in bullseye high

There are 8 open security issues in bullseye.

8 important issues:
  • CVE-2026-35328:
  • CVE-2026-35329:
  • CVE-2026-35330:
  • CVE-2026-35331:
  • CVE-2026-35332:
  • CVE-2026-35333:
  • CVE-2026-35334:
  • CVE-2026-47895: In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
Created: 2026-04-22 Last update: 2026-08-23 04:32
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 5-day delay is over. Check why.
Created: 2026-09-13 Last update: 2026-09-13 23:50
8 bugs tagged patch in the BTS normal
The BTS contains patches fixing 8 bugs, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-09-13 23:49
3 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit b32742997d4075e85a3120039e20a28546488e5d
Merge: 1dd7e0f9 d5645fe6
Author: Yves-Alexis Perez <corsac@debian.org>
Date:   Sun Sep 13 13:01:29 2026 +0000

    Merge branch 'sysusers' into 'debian/master'
    
    Install and use sysusers.d config file
    
    See merge request debian/strongswan!14

commit d5645fe6981bf178776358f548225ee23e79a155
Author: Luca Boccassi <luca.boccassi@gmail.com>
Date:   Thu Apr 23 20:00:00 2026 +0100

    Install and use sysusers.d config file
    
    sysusers.d config files allow a package to use declarative
    configuration instead of manually written maintainer scripts.
    This also allows image-based systems to be created with /usr/
    only, and also allows for factory resetting a system and
    recreating /etc/ on boot.
    
    debhelper already takes care of starting the init script
    on install with the generated snippet, so drop the manual
    start, to avoid ordering issues with the creation of the
    system user.
    
    https://www.freedesktop.org/software/systemd/man/latest/sysusers.d.html

commit 3f12bbc6155934c12e06bb1a94c4480672ee4ede
Author: Luca Boccassi <luca.boccassi@gmail.com>
Date:   Thu Apr 23 19:59:19 2026 +0100

    Stop deleting system user on remove/purge
    
    This is widely considered bad practice, as the kernel recycles
    UIDs/GIDs. So any potential leftover file/directory can then
    become owned by the next user/group that gets added, with
    unpredictable consequences.


https://salsa.debian.org/api/v4/projects/debian%2Fstrongswan API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-09-13 Last update: 2026-09-13 15:00
lintian reports 155 warnings normal
Lintian reports 155 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-09-09 Last update: 2026-09-09 00:00
debian/patches: 4 patches to forward upstream low

Among the 4 debian patches available in version 6.1.0-2 of the package, we noticed the following issues:

  • 4 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-09-08 16:01
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.1).
Created: 2025-02-27 Last update: 2026-09-12 16:32
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migration status for strongswan (6.0.7-1 to 6.1.0-2): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for strongswan/6.1.0-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass
    • ∙ ∙ Autopkgtest for vpnc/0.5.3+git20260629-1: amd64: Regression ♻ (reference ♻), arm64: No tests, superficial or marked flaky ♻ (reference ♻), armhf: No tests, superficial or marked flaky ♻, i386: No tests, superficial or marked flaky ♻, ppc64el: No tests, superficial or marked flaky ♻, riscv64: No tests, superficial or marked flaky ♻ (reference ♻)
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/s/strongswan.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 6 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-09-12] Accepted strongswan 6.0.1-6+deb13u7 (source) into proposed-updates (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-09-08] Accepted strongswan 6.1.0-2 (source) into unstable (Yves-Alexis Perez)
  • [2026-09-07] Accepted strongswan 6.1.0-1 (source) into unstable (Yves-Alexis Perez)
  • [2026-09-07] Accepted strongswan 6.0.1-6+deb13u7 (source) into stable-security (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-06-11] strongswan 6.0.7-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-08] Accepted strongswan 6.0.1-6+deb13u6 (source) into proposed-updates (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-06-08] Accepted strongswan 5.9.8-5+deb12u5 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-06-08] Accepted strongswan 6.0.1-6+deb13u6 (source) into stable-security (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-06-08] Accepted strongswan 5.9.8-5+deb12u5 (source) into oldstable-security (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-06-08] Accepted strongswan 6.0.7-1 (source) into unstable (Yves-Alexis Perez)
  • [2026-04-29] strongswan 6.0.6-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-26] Accepted strongswan 6.0.6-1 (source) into unstable (Yves-Alexis Perez)
  • [2026-04-25] Accepted strongswan 5.9.8-5+deb12u4 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-04-25] Accepted strongswan 6.0.1-6+deb13u5 (source) into proposed-updates (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-04-22] Accepted strongswan 6.0.1-6+deb13u5 (source) into stable-security (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-04-22] Accepted strongswan 5.9.8-5+deb12u4 (source) into oldstable-security (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-03-27] Accepted strongswan 5.9.1-1+deb11u6 (source) into oldoldstable-security (Thorsten Alteholz)
  • [2026-03-27] Accepted strongswan 5.9.8-5+deb12u3 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-03-27] Accepted strongswan 6.0.1-6+deb13u4 (source) into proposed-updates (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-03-26] strongswan 6.0.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-24] Accepted strongswan 6.0.5-1 (source) into unstable (Yves-Alexis Perez)
  • [2026-03-23] Accepted strongswan 5.9.8-5+deb12u3 (source) into oldstable-security (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2026-03-23] Accepted strongswan 6.0.1-6+deb13u4 (source) into stable-security (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2025-12-19] strongswan 6.0.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-15] Accepted strongswan 6.0.4-1 (source) into unstable (Yves-Alexis Perez)
  • [2025-11-29] Accepted strongswan 5.9.8-5+deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2025-11-29] Accepted strongswan 6.0.1-6+deb13u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Yves-Alexis Perez)
  • [2025-11-16] strongswan 6.0.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-13] Accepted strongswan 6.0.3-1 (source) into unstable (Yves-Alexis Perez) (signed by: Salvatore Bonaccorso)
  • [2025-11-03] Accepted strongswan 5.9.1-1+deb11u5 (source) into oldoldstable-security (Markus Koschany)
  • 1
  • 2
bugs [bug history graph]
  • all: 40 41
  • RC: 0
  • I&N: 27
  • M&W: 13 14
  • F&P: 0
  • patch: 8
links
  • homepage
  • lintian (0, 155)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (90, -)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 6.0.7-1ubuntu3
  • 8 bugs
  • patches for 6.0.7-1ubuntu3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing