From: Ankur Tyagi <[email protected]>
Use patch[1] provided by strongSwan as mentioned in the advisory[2].
[1] https://download.strongswan.org/security/CVE-2026-47895/strongswan-6.0.2-6.0.6_empty_id_clone.patch
[2] https://security-tracker.debian.org/tracker/CVE-2026-47895
Signed-off-by: Ankur Tyagi <[email protected]>
---
.../strongswan/CVE-2026-47895.patch | 92 +++++++++++++++++++
.../strongswan/strongswan_6.0.6.bb | 4 +-
2 files changed, 95 insertions(+), 1 deletion(-)
create mode 100644 meta-networking/recipes-support/strongswan/strongswan/CVE-2026-47895.patch
diff --git a/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-47895.patch b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-47895.patch
new file mode 100644
index 0000000000..b7cd22d0f7
--- /dev/null
+++ b/meta-networking/recipes-support/strongswan/strongswan/CVE-2026-47895.patch
@@ -0,0 +1,92 @@
+From ca03401ccf1c22966619d2c54176c78a647f9ce0 Mon Sep 17 00:00:00 2001
+From: "R. Elliott Childre" <[email protected]>
+Date: Mon, 18 May 2026 00:53:24 -0400
+Subject: [PATCH] identification: Fix double-free when cloning empty IDs
+
+The clone() method was missing a branch when there is an encoded chunk
+of length 0 that still needed to be cloned. Otherwise, the destruction
+of the clone frees the same pointer that the original owns.
+
+This double free was found with an improved `fuzz_ids` fuzz harness and
+a two byte input to create an identification from "@#" or [0x40, 0x23].
+It can also be triggered with `<type>:#` e.g. `dns:#`.
+
+One of the problematic constructors is used to parse EAP-Identities,
+which are cloned before storing them in the auth-cfg. So this can be
+triggered by an unauthenticated attacker.
+
+Note that while the length check was already added with 418dbd624363
+("cloning %any ID without zero-byte memleak") and identities that trigger
+this can be created since 86ab5636c2c9 ("support for @#hex ID_KEY_ID
+identification_t"), it was the referenced commit that made the length
+check problematic.
+
+Fixes: 2147da40a5d7 ("simplified identification_t.clone() using memcpy")
+Fixes: CVE-2026-47895
+
+CVE: CVE-2026-47895
+Upstream-Status: Backport [https://github.com/strongswan/strongswan/commit/075323d895f574424cfc4a5f491a1d388cdfda37]
+
+Signed-off-by: Ankur Tyagi <[email protected]>
+---
+ .../tests/suites/test_identification.c | 23 +++++++++++++++++++
+ src/libstrongswan/utils/identification.c | 2 +-
+ 2 files changed, 24 insertions(+), 1 deletion(-)
+
+diff --git a/src/libstrongswan/tests/suites/test_identification.c b/src/libstrongswan/tests/suites/test_identification.c
+index e7a4d4493e70..bb756399958e 100644
+--- a/src/libstrongswan/tests/suites/test_identification.c
++++ b/src/libstrongswan/tests/suites/test_identification.c
+@@ -1608,6 +1608,28 @@ START_TEST(test_clone)
+ }
+ END_TEST
+
++START_TEST(test_clone_empty)
++{
++ identification_t *a, *b;
++ chunk_t a_enc, b_enc;
++
++ /* this produces an empty but non-NULL encoding, which previously caused a
++ * double-free when destroying a clone */
++ a = identification_create_from_string("@#");
++ ck_assert(a != NULL);
++ a_enc = a->get_encoding(a);
++
++ b = a->clone(a);
++ ck_assert(b != NULL);
++ ck_assert(a != b);
++ b_enc = b->get_encoding(b);
++ ck_assert(a_enc.ptr != b_enc.ptr);
++
++ b->destroy(b);
++ a->destroy(a);
++}
++END_TEST
++
+ Suite *identification_suite_create()
+ {
+ Suite *s;
+@@ -1670,6 +1692,7 @@ Suite *identification_suite_create()
+
+ tc = tcase_create("clone");
+ tcase_add_test(tc, test_clone);
++ tcase_add_test(tc, test_clone_empty);
+ suite_add_tcase(s, tc);
+
+ return s;
+diff --git a/src/libstrongswan/utils/identification.c b/src/libstrongswan/utils/identification.c
+index 322c2c95ed9a..35837237c6c7 100644
+--- a/src/libstrongswan/utils/identification.c
++++ b/src/libstrongswan/utils/identification.c
+@@ -1722,7 +1722,7 @@ METHOD(identification_t, clone_, identification_t*,
+ clone->encoded = chunk_from_str(strdup(this->encoded.ptr));
+ compile_regex(clone);
+ }
+- else if (this->encoded.len)
++ else
+ {
+ clone->encoded = chunk_clone(this->encoded);
+ }
+--
+2.43.0
+
diff --git a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb
index daa6552899..d6176f000e 100644
--- a/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb
+++ b/meta-networking/recipes-support/strongswan/strongswan_6.0.6.bb
@@ -8,7 +8,9 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
DEPENDS = "flex-native flex bison-native"
DEPENDS:append = "${@bb.utils.contains('DISTRO_FEATURES', 'tpm2', ' tpm2-tss', '', d)}"
-SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2"
+SRC_URI = "https://download.strongswan.org/strongswan-${PV}.tar.bz2 \
+ file://CVE-2026-47895.patch \
+"
SRC_URI[sha256sum] = "07df7cedae56a7f3bb07e66d21a1f9f87e961db70e99184e11d3819413e4f87c"
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.