NEWS: Add info about CVE-2026-25075

This commit is contained in:
Tobias Brunner
2026-03-20 16:28:20 +01:00
parent 73aff21077
commit 01908d59b0
+4
View File
@@ -1,6 +1,10 @@
strongswan-6.0.5
----------------
- Fixed a vulnerability in the eap-ttls plugin related to processing EAP-TTLS
AVPs that can lead to a resource exhaustion or a crash.
This vulnerability has been registered as CVE-2026-25075.
- Added support for forwarding certain ICMP errors even if their source address
doesn't match the traffic selectors, when running on Linux 6.9+.