-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 13 Apr 2026 11:19:15 +0200 Source: strongswan Binary: charon-cmd charon-cmd-dbgsym charon-systemd charon-systemd-dbgsym libcharon-extauth-plugins libcharon-extauth-plugins-dbgsym libcharon-extra-plugins libcharon-extra-plugins-dbgsym libstrongswan libstrongswan-dbgsym libstrongswan-extra-plugins libstrongswan-extra-plugins-dbgsym libstrongswan-standard-plugins libstrongswan-standard-plugins-dbgsym strongswan-charon strongswan-charon-dbgsym strongswan-libcharon strongswan-libcharon-dbgsym strongswan-nm strongswan-nm-dbgsym strongswan-pki strongswan-pki-dbgsym strongswan-starter strongswan-starter-dbgsym strongswan-swanctl strongswan-swanctl-dbgsym Architecture: i386 Version: 5.9.8-5+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Yves-Alexis Perez Description: charon-cmd - standalone IPsec client charon-systemd - strongSwan IPsec client, systemd support libcharon-extauth-plugins - strongSwan charon library (extended authentication plugins) libcharon-extra-plugins - strongSwan charon library (extra plugins) libstrongswan - strongSwan utility and crypto library libstrongswan-extra-plugins - strongSwan utility and crypto library (extra plugins) libstrongswan-standard-plugins - strongSwan utility and crypto library (standard plugins) strongswan-charon - strongSwan Internet Key Exchange daemon strongswan-libcharon - strongSwan charon library strongswan-nm - strongSwan plugin to interact with NetworkManager strongswan-pki - strongSwan IPsec client, pki command strongswan-starter - strongSwan daemon starter and configuration file parser strongswan-swanctl - strongSwan IPsec client, swanctl command Changes: strongswan (5.9.8-5+deb12u4) bookworm-security; urgency=medium . * d/patches: add fix for integer underflow in libsimaka when handling EAP-SIM/AKA attributes (CVE-2026-35330) * d/patches: add fix for integer underflow in libradius when handling RADIUS attributes (CVE-2026-35333) * d/patches: add fix for NULL-pointer dereference in libtls when handling ECDH public values (CVE-2026-35332) * d/patches: add fix for infinite loop in libtls when handling supported versions TLS extension (CVE-2026-35328) * d/patches: add fix for NULL-pointer dereference in libstrongswan (pkcs5) and the pkcs7 plugin when processing padding in PKCS#7 (CVE-2026-35329) * d/patches: add fix for acceptation of authentication certificates violating name constraints (CVE-2026-35331) * d/patches: add fix for possible NULL-pointer dereference in gmp plugin for RSA decryption (CVE-2026-35334) Checksums-Sha1: 2b09c9e108dc35bb6fb15b8c76c8d57d27816f54 81600 charon-cmd-dbgsym_5.9.8-5+deb12u4_i386.deb 0e68f9e2216029099e9301925282157f4923bb14 89028 charon-cmd_5.9.8-5+deb12u4_i386.deb 3482de6912dd924d977ad0eda317103080f2bb14 51344 charon-systemd-dbgsym_5.9.8-5+deb12u4_i386.deb 9b276304b043166f2dccc4d8b0398357fab01481 85148 charon-systemd_5.9.8-5+deb12u4_i386.deb 299ab15e6c33aa8de6492249a2669823ba20de9c 129852 libcharon-extauth-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb 97523fbcc1ff287aeeebfc747ba64bbff12e3050 90116 libcharon-extauth-plugins_5.9.8-5+deb12u4_i386.deb 3399e06a06c97dd7c4709f27560a9269f2a39f9c 1459552 libcharon-extra-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb bf7e425b7a529b5c82c53fdbb2f12e4173b1e108 292696 libcharon-extra-plugins_5.9.8-5+deb12u4_i386.deb c3372d380b113fa976f1915ad2c5053c972f343c 1382724 libstrongswan-dbgsym_5.9.8-5+deb12u4_i386.deb 24df3679a063aa98d6316b2129c7f6f9b0a18563 608736 libstrongswan-extra-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb d9f1d121b0daeeb607a17d53b4d7894ae5529d44 281396 libstrongswan-extra-plugins_5.9.8-5+deb12u4_i386.deb 1994748d2cd933817edb80978efedde047ed227c 432148 libstrongswan-standard-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb 25f62f6af4843cbb9c22fcb7f8708ed87ca31a52 145292 libstrongswan-standard-plugins_5.9.8-5+deb12u4_i386.deb 73ed050caccadb98a22749d98ffe4ff961e823e0 452984 libstrongswan_5.9.8-5+deb12u4_i386.deb 1fa185eb5aed31d1fb2b28141b4ee0d0f5a367b7 51872 strongswan-charon-dbgsym_5.9.8-5+deb12u4_i386.deb 877c80a6c3d9763fdad92f27f9f700623fcabe9c 89404 strongswan-charon_5.9.8-5+deb12u4_i386.deb 2fe128032fd510fff5338b652a448592dae95585 950592 strongswan-libcharon-dbgsym_5.9.8-5+deb12u4_i386.deb dcf09e26d68f8d7e90fb80a7ae64588beb22302b 350524 strongswan-libcharon_5.9.8-5+deb12u4_i386.deb 3be2dde1c69c8809750ad9be972032e95c44a462 110384 strongswan-nm-dbgsym_5.9.8-5+deb12u4_i386.deb 026980b8f585eae67607c24004aa16457dfc6e28 93472 strongswan-nm_5.9.8-5+deb12u4_i386.deb 1dcb2a5cc3c3d66ebb6b4f4cf49e05a4338157fe 118736 strongswan-pki-dbgsym_5.9.8-5+deb12u4_i386.deb 014aa0505646e3e297d8a33f44c68fb5d28758b7 146748 strongswan-pki_5.9.8-5+deb12u4_i386.deb 9609e6702cf49e009ea725f9973f7bf2fb56dee4 284784 strongswan-starter-dbgsym_5.9.8-5+deb12u4_i386.deb f60063a3d7ffac89f81e17759b15b5b0f9a91227 218940 strongswan-starter_5.9.8-5+deb12u4_i386.deb a9d45122808232204477403f5f1f8169b1526e3a 314764 strongswan-swanctl-dbgsym_5.9.8-5+deb12u4_i386.deb fa320b601c48ccb63445029bbaa18b661dc77381 189652 strongswan-swanctl_5.9.8-5+deb12u4_i386.deb b3ac39db3c8cf034dcb983c98c60609bf97b3a43 17988 strongswan_5.9.8-5+deb12u4_i386-buildd.buildinfo Checksums-Sha256: 58100873af28627205de4c4010153581ebb1f62bf9c486733b9eb709ea4420eb 81600 charon-cmd-dbgsym_5.9.8-5+deb12u4_i386.deb 70ec9fe23383c3e135fcb48bfaa1ff6f2d429d20c368cf67d6533a82d12d8dbb 89028 charon-cmd_5.9.8-5+deb12u4_i386.deb dbef4ebbaf50d4e28749601004481702fd0e131abb1aa5c6f7ec61a990da2621 51344 charon-systemd-dbgsym_5.9.8-5+deb12u4_i386.deb 193bffda518be63f88539ab27b8d07075f45449613e9f56a46fd90b81c5e820b 85148 charon-systemd_5.9.8-5+deb12u4_i386.deb 8bfa45c4114341f76cf5b649c9ce9499b6242d898b3b902d3a908f46aae0ca4e 129852 libcharon-extauth-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb 946af17c41957811605a57b14ce0b3dc1d84d8f6c44e32f7d389b92f989a7838 90116 libcharon-extauth-plugins_5.9.8-5+deb12u4_i386.deb c61e7640bd88ba220e38a656a0307440b3dfe0caa8814e8396df799c56007edb 1459552 libcharon-extra-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb 2d42a82157802b3eaeeb5d80a8224319a6382ef4450941c634d3b6412fcfac4d 292696 libcharon-extra-plugins_5.9.8-5+deb12u4_i386.deb 8602cc177e650e12c4ac94d40dc745e72324140ee645122579b485d86fedd49c 1382724 libstrongswan-dbgsym_5.9.8-5+deb12u4_i386.deb 5bb18596af70e218665d8f6e7babcb17ef5b637d309b234589ad7d520dddb269 608736 libstrongswan-extra-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb 437c8408c57df99cd37b1717684cb946d2953aa3912696653544af1ce2961d1c 281396 libstrongswan-extra-plugins_5.9.8-5+deb12u4_i386.deb 1acaf00490e5caa881f86e302ffb20e914c173cb02f71ee56fa8d9d629ce0613 432148 libstrongswan-standard-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb dfedf824d0f8ae2238a47566860b4959dfcad55bdb9ddb418579d2471da88798 145292 libstrongswan-standard-plugins_5.9.8-5+deb12u4_i386.deb abc7155f17870f471721227875126eaae12bb42495da7c0bf19412db60ca5f79 452984 libstrongswan_5.9.8-5+deb12u4_i386.deb 6754ee0ad77422a0a9fc6621cf14babf04bcbcec4450f8faf709658ed09661a1 51872 strongswan-charon-dbgsym_5.9.8-5+deb12u4_i386.deb 0bedae0b5069f900bd29f211e49b1b2cc60ad59e3f0d38d47b855b8f8ee1abf7 89404 strongswan-charon_5.9.8-5+deb12u4_i386.deb a9ad284636a301f4a120ccaea6e931ae7f6af5ebb5bcc40b8b2d1f360376d987 950592 strongswan-libcharon-dbgsym_5.9.8-5+deb12u4_i386.deb f45b3f449933f034329d70901571eb6cc6cbb5c01bb67cc2006ce01778ab48e7 350524 strongswan-libcharon_5.9.8-5+deb12u4_i386.deb 16b58dc2f56d08d5568482c8fc15aa87c9da90f55b5b65146c2f096e29135483 110384 strongswan-nm-dbgsym_5.9.8-5+deb12u4_i386.deb 8d586e41d1c3edc88678449345864a78b70d9257593a0f7d3eca43b5cff5845a 93472 strongswan-nm_5.9.8-5+deb12u4_i386.deb 8cb5a8b8619561c02ebcd60d2d5ee81f93459b30e92185baf25d360ba9d517bf 118736 strongswan-pki-dbgsym_5.9.8-5+deb12u4_i386.deb 401429c2d5c694d3b95ed15195932d9072b6611f9005bbe0213428c0e12cd98a 146748 strongswan-pki_5.9.8-5+deb12u4_i386.deb 53660ccdd235cf92e83d11b84db0e5d8adcd9e5a7238ef4a251e7ef678a25411 284784 strongswan-starter-dbgsym_5.9.8-5+deb12u4_i386.deb 3473ba44f44a8c4235fafc6039666549c47cae452482dc894efd0a2d3537c548 218940 strongswan-starter_5.9.8-5+deb12u4_i386.deb 8fc8a3bf047e6b4b0c5ffc5dae1f8b3df1f178543f487801594f06f67d1e4475 314764 strongswan-swanctl-dbgsym_5.9.8-5+deb12u4_i386.deb f3a16215fea87e37bdb390b92d640f171ff9cc1d00dd113f4453093b77c45952 189652 strongswan-swanctl_5.9.8-5+deb12u4_i386.deb 2681599a5404dbf48816c23ce16d1e03ec6377632f5d4bbf2791fca3be8ba82d 17988 strongswan_5.9.8-5+deb12u4_i386-buildd.buildinfo Files: e6d95464ee3605208eda7dc436bb4d28 81600 debug optional charon-cmd-dbgsym_5.9.8-5+deb12u4_i386.deb 9af490950b00a4b8f3bbf3a7da65959a 89028 net optional charon-cmd_5.9.8-5+deb12u4_i386.deb a10e541bb82c8efd7b29bcb813adafbd 51344 debug optional charon-systemd-dbgsym_5.9.8-5+deb12u4_i386.deb 1972bd8de9822992d57361694b42defd 85148 net optional charon-systemd_5.9.8-5+deb12u4_i386.deb ad0addd9bcc062829a769c84bbc9d68f 129852 debug optional libcharon-extauth-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb 22882b2f148e1e07987850ba49a580b5 90116 net optional libcharon-extauth-plugins_5.9.8-5+deb12u4_i386.deb d011716737abf8ea5b95eb6397f6befe 1459552 debug optional libcharon-extra-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb 4aee1c9438700d1c353a384e4aed915d 292696 net optional libcharon-extra-plugins_5.9.8-5+deb12u4_i386.deb bbf3c843d98809db86e6d7266f537de2 1382724 debug optional libstrongswan-dbgsym_5.9.8-5+deb12u4_i386.deb e6ae2b03d539a5038b0d209b64cd6158 608736 debug optional libstrongswan-extra-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb 9b89a7dbff8508741ebbe8922dadfb35 281396 net optional libstrongswan-extra-plugins_5.9.8-5+deb12u4_i386.deb f4fc20c6d064184ad63587912cbf348d 432148 debug optional libstrongswan-standard-plugins-dbgsym_5.9.8-5+deb12u4_i386.deb 9173606d491deb2f6896c7260e52430a 145292 net optional libstrongswan-standard-plugins_5.9.8-5+deb12u4_i386.deb c0894de7c12831fd6ef4fc506802a1e0 452984 net optional libstrongswan_5.9.8-5+deb12u4_i386.deb a843e45870624ac7ffc7c5c282d87b38 51872 debug optional strongswan-charon-dbgsym_5.9.8-5+deb12u4_i386.deb da82a6f2577238fb4dfa0768560aa84f 89404 net optional strongswan-charon_5.9.8-5+deb12u4_i386.deb 33176d7af165f0b396dd9d1fb2ab1ea9 950592 debug optional strongswan-libcharon-dbgsym_5.9.8-5+deb12u4_i386.deb 93d40031cdc1642085f7447b6158e6b5 350524 net optional strongswan-libcharon_5.9.8-5+deb12u4_i386.deb 15e59063825c044bb6ab13a06dc5df92 110384 debug optional strongswan-nm-dbgsym_5.9.8-5+deb12u4_i386.deb adfed4b8d9946c069138f1645739cfa8 93472 net optional strongswan-nm_5.9.8-5+deb12u4_i386.deb b9f67b5318af642dd8ef26b271ef3206 118736 debug optional strongswan-pki-dbgsym_5.9.8-5+deb12u4_i386.deb 347acc7dd7fc18f9f1fdc8b840acb026 146748 net optional strongswan-pki_5.9.8-5+deb12u4_i386.deb 23c3c280607211ab497604202e753a35 284784 debug optional strongswan-starter-dbgsym_5.9.8-5+deb12u4_i386.deb 6a83d6911357557a0c1ce2c41e39434e 218940 net optional strongswan-starter_5.9.8-5+deb12u4_i386.deb 60c718eba325b006f6a5655a9087222c 314764 debug optional strongswan-swanctl-dbgsym_5.9.8-5+deb12u4_i386.deb 3d6b7dfa63ec71ba02f16096351b9105 189652 net optional strongswan-swanctl_5.9.8-5+deb12u4_i386.deb 40f64a51b8c71ebaac4a924659a5e72c 17988 net optional strongswan_5.9.8-5+deb12u4_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE+i/sCsF3puL4e7qIGNGWmfrqILEFAmned7QACgkQGNGWmfrq ILFsUg/+OPxdm/xppQ854112XP1LNwDwlPAgZhLeIOUlrBLp8vvdqonJLWHTUqM3 KuHxi0FJGuw5Mw6WmRed5lT5CCoWGdZtRrMt7aeep/0J1MQOSrEUApl4IaXmi60C Ff+HvIVDPRiR+gwsxfhJ7SdEPRDGixo+bexBJCRPPhlx1egaAcMOXvcvlOO132UO nId84PBmdeo7AumOSl0JQLDG8kKI0QibkjhEZ0Fz1PowlHpifaFZV0aDUIuFPm// S6HOZmbAzQWTmlNXBz4ej3gWCi6BYgCJvWhXm8U/RnqDIL/aHCmumibzK8RSeyTS WKc7JOKdoJSgvh3io/JM7r8rYFcBgjeAHipSxDuAqCuPk2kjHp04ZDyF6yNggWEa IVs4wgBNSaPQrTMDd1opCA8zNbGtOv3Bj4lSytkRX80cjOgsBIpXmd8GNMEm7OrN jIz/wycgHG2cdZJZxjd7wvt3TpNkbNHh5Y9ROhSOdMeCsPtlPoJgZiYtraW2ogsq HktAzsafF5b6Icbs4SfVLItkq8JDGT5OcNrWmvqqcM2dWt44+x1a9sxIdKAoU2T/ lMcvHzaY1hX/m+8Y+cVZ4i1p1oxkR2AYEn74ttIQ3jaUSqiH9g1qVeRqVl8VQsAP KdwTAqPyMU8xW2y7OpaGlRG4xzLb1k/2iucr1J/ezEd0VyZRzXo= =XsZI -----END PGP SIGNATURE-----