-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 13 Apr 2026 11:19:15 +0200 Source: strongswan Binary: charon-cmd charon-cmd-dbgsym charon-systemd charon-systemd-dbgsym libcharon-extauth-plugins libcharon-extauth-plugins-dbgsym libcharon-extra-plugins libcharon-extra-plugins-dbgsym libstrongswan libstrongswan-dbgsym libstrongswan-extra-plugins libstrongswan-extra-plugins-dbgsym libstrongswan-standard-plugins libstrongswan-standard-plugins-dbgsym strongswan-charon strongswan-charon-dbgsym strongswan-libcharon strongswan-libcharon-dbgsym strongswan-nm strongswan-nm-dbgsym strongswan-pki strongswan-pki-dbgsym strongswan-starter strongswan-starter-dbgsym strongswan-swanctl strongswan-swanctl-dbgsym Architecture: amd64 Version: 5.9.8-5+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Yves-Alexis Perez Description: charon-cmd - standalone IPsec client charon-systemd - strongSwan IPsec client, systemd support libcharon-extauth-plugins - strongSwan charon library (extended authentication plugins) libcharon-extra-plugins - strongSwan charon library (extra plugins) libstrongswan - strongSwan utility and crypto library libstrongswan-extra-plugins - strongSwan utility and crypto library (extra plugins) libstrongswan-standard-plugins - strongSwan utility and crypto library (standard plugins) strongswan-charon - strongSwan Internet Key Exchange daemon strongswan-libcharon - strongSwan charon library strongswan-nm - strongSwan plugin to interact with NetworkManager strongswan-pki - strongSwan IPsec client, pki command strongswan-starter - strongSwan daemon starter and configuration file parser strongswan-swanctl - strongSwan IPsec client, swanctl command Changes: strongswan (5.9.8-5+deb12u4) bookworm-security; urgency=medium . * d/patches: add fix for integer underflow in libsimaka when handling EAP-SIM/AKA attributes (CVE-2026-35330) * d/patches: add fix for integer underflow in libradius when handling RADIUS attributes (CVE-2026-35333) * d/patches: add fix for NULL-pointer dereference in libtls when handling ECDH public values (CVE-2026-35332) * d/patches: add fix for infinite loop in libtls when handling supported versions TLS extension (CVE-2026-35328) * d/patches: add fix for NULL-pointer dereference in libstrongswan (pkcs5) and the pkcs7 plugin when processing padding in PKCS#7 (CVE-2026-35329) * d/patches: add fix for acceptation of authentication certificates violating name constraints (CVE-2026-35331) * d/patches: add fix for possible NULL-pointer dereference in gmp plugin for RSA decryption (CVE-2026-35334) Checksums-Sha1: dbed3887e487a190a6f5c25c2324315490a89039 77484 charon-cmd-dbgsym_5.9.8-5+deb12u4_amd64.deb 3cd8bfbb1d3797d9fa7ddf34789f70d4a85705e0 88512 charon-cmd_5.9.8-5+deb12u4_amd64.deb 8539279d7d10d4ddb6a4b5c5c10746417d0f82ba 52936 charon-systemd-dbgsym_5.9.8-5+deb12u4_amd64.deb f0ec8ce05c34371f7a829ee51c4a03c096f481fc 85016 charon-systemd_5.9.8-5+deb12u4_amd64.deb 7ed7fb0969e87e478f951bbdc34482704bbc39e9 117908 libcharon-extauth-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb 3e4153cf5f74fd8e3bcfd5ff30733cd5f64b1c96 89292 libcharon-extauth-plugins_5.9.8-5+deb12u4_amd64.deb 66e65e7560cdbc3477d0be4e3a4014075f24d5d1 1502684 libcharon-extra-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb fea317b88d34ae5827214d7f60535dbb161f1b2f 273444 libcharon-extra-plugins_5.9.8-5+deb12u4_amd64.deb c0607011fe251f53f15f1addf65cee3a7485cac4 1466468 libstrongswan-dbgsym_5.9.8-5+deb12u4_amd64.deb 5ff1ba8653161334cde3a96e6d99ce6b3a09e791 609804 libstrongswan-extra-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb f311d96b4d862f2f79a917cd773f2f462522f54e 270788 libstrongswan-extra-plugins_5.9.8-5+deb12u4_amd64.deb 9420d7e2066264a8f3499b860066e332f509b27e 444696 libstrongswan-standard-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb d419b300de3986655aa3208c68fd03b84a8fdffd 139372 libstrongswan-standard-plugins_5.9.8-5+deb12u4_amd64.deb 0e0ab0b50361d19f274f515fa0ebf277175ed62c 431284 libstrongswan_5.9.8-5+deb12u4_amd64.deb dc35a0cf60f3c066bfb8adb95d37d99cba055152 53172 strongswan-charon-dbgsym_5.9.8-5+deb12u4_amd64.deb 6ef5332f1eda4ae20e0db5dfbb6a3e383e6de84c 89468 strongswan-charon_5.9.8-5+deb12u4_amd64.deb a20269a7b674bbc430a040702520ab08bb2d54d2 1034016 strongswan-libcharon-dbgsym_5.9.8-5+deb12u4_amd64.deb 1807549a3f98b34b84af817fe17982bd79c86947 317672 strongswan-libcharon_5.9.8-5+deb12u4_amd64.deb 66161e8d73c8358174816163ece82c89faa51396 99952 strongswan-nm-dbgsym_5.9.8-5+deb12u4_amd64.deb 49b335d5581eb502847569fd3b27abb03b8c1196 91724 strongswan-nm_5.9.8-5+deb12u4_amd64.deb 0d0366148abe39628c74fc89077005a662fd85bc 124748 strongswan-pki-dbgsym_5.9.8-5+deb12u4_amd64.deb 6e3237f0eb8906bef206e6e97c9c3c5a884fd486 144432 strongswan-pki_5.9.8-5+deb12u4_amd64.deb bf8bcff3ecf0685bcddb14099989d4f3fd344736 294888 strongswan-starter-dbgsym_5.9.8-5+deb12u4_amd64.deb 101e2ad14afe5873ab81bc5188e2bc0d00105151 213336 strongswan-starter_5.9.8-5+deb12u4_amd64.deb 3aa72df7ce4bd6cf7c13b3e49e12a630c2a182b0 367712 strongswan-swanctl-dbgsym_5.9.8-5+deb12u4_amd64.deb a9d111f6f0cee02d26a8ae34b1a04595d5e37921 180684 strongswan-swanctl_5.9.8-5+deb12u4_amd64.deb 4e9131fe81e2a46aef5154a826be6495fbe39035 18136 strongswan_5.9.8-5+deb12u4_amd64-buildd.buildinfo Checksums-Sha256: 25bad6c7e3734200732d51245f7c9af51cf37adde877211ace60885da2ffbbe9 77484 charon-cmd-dbgsym_5.9.8-5+deb12u4_amd64.deb 2fa964b07688c426ceb72a7d2537f505214b1cba97b0918bc8852eb957c963b5 88512 charon-cmd_5.9.8-5+deb12u4_amd64.deb c18a3f4422b90a6544bbd5231fc0b10ff80720e1646574a814f390acae7e99e1 52936 charon-systemd-dbgsym_5.9.8-5+deb12u4_amd64.deb 1ba4649d6a1a0d8b7b012800041cdf53cbd2c8992abde0af0219e6bcaddd79fd 85016 charon-systemd_5.9.8-5+deb12u4_amd64.deb 3e61a8314073aee6c012f0e40fdc4e41b7da39dbc127ab70e86d3f5ee2653d26 117908 libcharon-extauth-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb af441d0dadf1fbf1eb801dcb6576adb86d41873852337365a32150f00b0666f8 89292 libcharon-extauth-plugins_5.9.8-5+deb12u4_amd64.deb 91c3a3635295380b43083fe3e91a1315c23be94db6ce7009c7a0e5aea666a4bb 1502684 libcharon-extra-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb a0848c0111f40a7105bdf593b2607d4c8dd83767b263308283d3ff7183863ac8 273444 libcharon-extra-plugins_5.9.8-5+deb12u4_amd64.deb 0992aaa7874582279a82827dfcf7855466832b554f597b793c42d2a6fb37d607 1466468 libstrongswan-dbgsym_5.9.8-5+deb12u4_amd64.deb 5bfd720afbd42b5c7913b78be34f9d0681b28bef91863075eab64b50802eb7dc 609804 libstrongswan-extra-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb 91d30187dfb76abb72c10bcaec5cfcb1c987d647e5c8c4a880be1613a1988f1b 270788 libstrongswan-extra-plugins_5.9.8-5+deb12u4_amd64.deb e0a4ff8190dd8fbeab6cbce110562d7e0c4b0ee5711950fa51e571f384717c6f 444696 libstrongswan-standard-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb d28c019e3fafec9f08b300a718b809ab044211cf5b11ff6e232e83123fa8f01e 139372 libstrongswan-standard-plugins_5.9.8-5+deb12u4_amd64.deb 289064d3f1533541f60f1e42b78a535d767f3017637bfe5a00e18dc7c21e3e54 431284 libstrongswan_5.9.8-5+deb12u4_amd64.deb 7e2da9caa8691cb0a21061255315b84314542fbc7d2682c1bc225dba603def38 53172 strongswan-charon-dbgsym_5.9.8-5+deb12u4_amd64.deb eb360e4edf9d5e775c406449264ce91c3c1b17e3448c52ac02f496c2bba76fd6 89468 strongswan-charon_5.9.8-5+deb12u4_amd64.deb 1a1afc582d17420b04b20e815acb7e5e57b4b099891cf8d1b8c62215a479e3f6 1034016 strongswan-libcharon-dbgsym_5.9.8-5+deb12u4_amd64.deb d3f9b12db1d1e2523298636b01ea212cf321daff737c45150ca6db269ed2b73c 317672 strongswan-libcharon_5.9.8-5+deb12u4_amd64.deb b71fcdcb764390ce89aa8899f701cf27e0e3b2f21fbfa4b46a1a376f7e038b91 99952 strongswan-nm-dbgsym_5.9.8-5+deb12u4_amd64.deb 2659206d42ed618c830e87c964c6c10ee498886d8b8d635d95e04bc599118bff 91724 strongswan-nm_5.9.8-5+deb12u4_amd64.deb 0bbd3466747a395e166e2f52e86fb8f6c54d622e83a14b58579491f9fd652caf 124748 strongswan-pki-dbgsym_5.9.8-5+deb12u4_amd64.deb 6dfc09cdbb277db793086771ee016a0f5234fe773501bf5b36a986c4fb32d551 144432 strongswan-pki_5.9.8-5+deb12u4_amd64.deb eff4a245d94c1b67983cf6354cee77ebb289df6c085725c9e22ab3359b2084f8 294888 strongswan-starter-dbgsym_5.9.8-5+deb12u4_amd64.deb 6711001a441f4d411dfe4dc4b43491894b7e5871e3b938b9c61504a65270317c 213336 strongswan-starter_5.9.8-5+deb12u4_amd64.deb af91ae8c01fa4f0170fd743fef60983397159039f90d8c30395797188d6e8d9a 367712 strongswan-swanctl-dbgsym_5.9.8-5+deb12u4_amd64.deb 338357992a0928a7f5e47f6b38f33783930b21f06e0ea3da80bec7bd1f2151f0 180684 strongswan-swanctl_5.9.8-5+deb12u4_amd64.deb 8bcd9cd5cab3f56b54902c6f05f3b1218c3c8e0a62947ab90e0a4e148de2159a 18136 strongswan_5.9.8-5+deb12u4_amd64-buildd.buildinfo Files: ef13189dc1a03787c53447a58aea69c5 77484 debug optional charon-cmd-dbgsym_5.9.8-5+deb12u4_amd64.deb 4372b86026cc656316e2be3c84a72b41 88512 net optional charon-cmd_5.9.8-5+deb12u4_amd64.deb 190cfc184a9dfd86c56b15fdada735c4 52936 debug optional charon-systemd-dbgsym_5.9.8-5+deb12u4_amd64.deb 3229f593ab7a0f42f8f2d9df68b5d378 85016 net optional charon-systemd_5.9.8-5+deb12u4_amd64.deb 42d71ee571c7e55eebd861f4df5fafc1 117908 debug optional libcharon-extauth-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb 422a58979552561cae9ab464ccb2d9f3 89292 net optional libcharon-extauth-plugins_5.9.8-5+deb12u4_amd64.deb 76df4269f8dbdcc34e5cbd1066ee227f 1502684 debug optional libcharon-extra-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb ac6c3f03c534c1ca4658c3d8ee47479e 273444 net optional libcharon-extra-plugins_5.9.8-5+deb12u4_amd64.deb 64d08bb226820a39e6904abd8bb3bca6 1466468 debug optional libstrongswan-dbgsym_5.9.8-5+deb12u4_amd64.deb 21db95d7a1c312285f2be2994388ba88 609804 debug optional libstrongswan-extra-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb fab10e053212ce391811209a135d26a8 270788 net optional libstrongswan-extra-plugins_5.9.8-5+deb12u4_amd64.deb 6b83cb1bbb98fa0f0e266deabd303816 444696 debug optional libstrongswan-standard-plugins-dbgsym_5.9.8-5+deb12u4_amd64.deb 59213a8f1ef9ec52d7e73cf43ad23f83 139372 net optional libstrongswan-standard-plugins_5.9.8-5+deb12u4_amd64.deb 3da3672c090106ebaf6febfea12bc197 431284 net optional libstrongswan_5.9.8-5+deb12u4_amd64.deb 8dcf216369f86553204578cb56cafa5f 53172 debug optional strongswan-charon-dbgsym_5.9.8-5+deb12u4_amd64.deb 58ae7584e915ea201c301ec22c63cdd4 89468 net optional strongswan-charon_5.9.8-5+deb12u4_amd64.deb 81437a3e130ed38274fccd9a50cf8ede 1034016 debug optional strongswan-libcharon-dbgsym_5.9.8-5+deb12u4_amd64.deb b65dcd8502c5d10c78a9ba96d888fca5 317672 net optional strongswan-libcharon_5.9.8-5+deb12u4_amd64.deb be54f0c1bb2a268d00516ae1df4ff76a 99952 debug optional strongswan-nm-dbgsym_5.9.8-5+deb12u4_amd64.deb 3751050c8381180cfc77338256e0207c 91724 net optional strongswan-nm_5.9.8-5+deb12u4_amd64.deb 365a5860f2942da7c06ffb82c7d42ac1 124748 debug optional strongswan-pki-dbgsym_5.9.8-5+deb12u4_amd64.deb 02c5507a6eaef87ece310dc51527ac42 144432 net optional strongswan-pki_5.9.8-5+deb12u4_amd64.deb 1eebb0847b345e8b75dd33fd7b8355ba 294888 debug optional strongswan-starter-dbgsym_5.9.8-5+deb12u4_amd64.deb 604d70997908dc4d338cf17ac7830aed 213336 net optional strongswan-starter_5.9.8-5+deb12u4_amd64.deb 53382df2f07234d2b23cb9c529f02530 367712 debug optional strongswan-swanctl-dbgsym_5.9.8-5+deb12u4_amd64.deb 80c5a45423489169891a4620ec403f2c 180684 net optional strongswan-swanctl_5.9.8-5+deb12u4_amd64.deb 4251d06530123b548f664cd8edce32a4 18136 net optional strongswan_5.9.8-5+deb12u4_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7cQ9mRD4+dWjjrb6PkCWRKsh20cFAmneeAQACgkQPkCWRKsh 20doWBAAsjv8tpigphFsMGVipGU0KURsS2Z2g/ysmr3ovw9T5eqmE2+gUU0h24Jz JxMrNfXmaJdy1d/TofK36+kORy9fZyfO1tcCxzC22vvhi2hIhyPhfVyX/KnHW0p3 Tu3fMcjmcQlmvRmvCz7dklB3l1sUw8mi0qokJ6CE5QCnPGuUKwgqat+AsD75Yk9m DVd6fg0aXsCZoP8nD54wsdScpIsoQBh+zRw0r0F2FthkKuifx7DfV36/dLHJtrCZ qeUE60EO5hqcWOgKWivI2DdQClLeruxjVpPtoU1uBoof1HkQztUvqQAyZq3PXB4R uiDR+Rf0Xwud8u4BTKsHivcrWI6vDmaLfAHz3ZGKVh03alT9oZLpKOq/Rg/DMM1A cWjPC4difdV5fB+8/zeNy2+gCR37LN5wAbkRIr+3QO+fSlktDXsZHAiGu/PQKMkB ywfv7S4QWeBthlrOrQHKQWfYPVr5ISSCL4t/fGynCqwfAgSpj60rTmG0+eBxY7QY rY4m0zrkI5O5Kz+0fN1M5C9WRO/EyUlRORNGhbDV5lneoGB3hoor3GrRl6bnGTRY 105grMcbxck9QCQOEdHFORPwQCKgU8MoKSqJYpRo/fzeo0bDyUDqUh4xPzDJuugL tg38DA/zCbLdCBgSQlNT/DdhxngP9f9mYYKTnw1BZoqIjuCWDIc= =+1Dg -----END PGP SIGNATURE-----