This update for strongswan fixes the following issues
* CVE-2026-35328: infinite loop when handling supported versions TLS extension
(bsc#1261712).
* CVE-2026-35329: null pointer dereference when processing padding in PKCS#7
(bsc#1261717).
* CVE-2026-35330: integer underflow when handling EAP-SIM/AKA attributes
(bsc#1261705).
* CVE-2026-35331: accepting certificates violating name constraints
(bsc#1261718).
* CVE-2026-35332: null pointer dereference when handling ECDH public value in
TLS (bsc#1261708).
* CVE-2026-35333: integer underflow when handling RADIUS attributes
(bsc#1261706).
* CVE-2026-35334: possible null pointer dereference in RSA decryption
(bsc#1261720).
* CVE-2026-47895: double-free when destroying certain cloned identities
(bsc#1266360).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2368=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2368=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-2368=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2368=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2368=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* strongswan-libs0-5.9.11-150400.19.35.1
* strongswan-5.9.11-150400.19.35.1
* strongswan-ipsec-debuginfo-5.9.11-150400.19.35.1
* strongswan-debuginfo-5.9.11-150400.19.35.1
* strongswan-debugsource-5.9.11-150400.19.35.1
* strongswan-ipsec-5.9.11-150400.19.35.1
* strongswan-hmac-5.9.11-150400.19.35.1
* strongswan-libs0-debuginfo-5.9.11-150400.19.35.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* strongswan-doc-5.9.11-150400.19.35.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* strongswan-libs0-5.9.11-150400.19.35.1
* strongswan-5.9.11-150400.19.35.1
* strongswan-ipsec-debuginfo-5.9.11-150400.19.35.1
* strongswan-debuginfo-5.9.11-150400.19.35.1
* strongswan-debugsource-5.9.11-150400.19.35.1
* strongswan-ipsec-5.9.11-150400.19.35.1
* strongswan-hmac-5.9.11-150400.19.35.1
* strongswan-libs0-debuginfo-5.9.11-150400.19.35.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
*...
Read the Full Advisory* bsc#1261705
* bsc#1261706
* bsc#1261708
* bsc#1261712
* bsc#1261717
* bsc#1261718
* bsc#1261720
* bsc#1266360
## References:
* https://www.suse.com/security/cve/CVE-2026-35328.html
* https://www.suse.com/security/cve/CVE-2026-35329.html
* https://www.suse.com/security/cve/CVE-2026-35330.html
* https://www.suse.com/security/cve/CVE-2026-35331.html
* https://www.suse.com/security/cve/CVE-2026-35332.html
* https://www.suse.com/security/cve/CVE-2026-35333.html
* https://www.suse.com/security/cve/CVE-2026-35334.html
* https://www.suse.com/security/cve/CVE-2026-47895.html
* https://bugzilla.suse.com/show_bug.cgi?id=1261705
* https://bugzilla.suse.com/show_bug.cgi?id=1261706
* https://bugzilla.suse.com/show_bug.cgi?id=1261708
* https://bugzilla.suse.com/show_bug.cgi?id=1261712
* https://bugzilla.suse.com/show_bug.cgi?id=1261717
* https://bugzilla.suse.com/show_bug.cgi?id=1261718
* https://bugzilla.suse.com/show_bug.cgi?id=1261720
* https://bugzilla.suse.com/show_bug.cgi?id=1266360
Get the latest Linux and open source security news straight to your inbox.