20067 Commits
Author SHA1 Message Date
Tobias Brunner 9326e4707b github: Remove installation of unnecessary debug symbols for OpenSSL
These are apparently not necessary anymore and since there are often
sync issues (package version mismatch if security fixes are shipped
because there is no *-security suite in the ddebs repo), lets not
install them anymore.
2026-06-29 17:50:32 +02:00
Tobias Brunner 02ade69543 vici: Update supported Python versions
Debian bullseye still ships 3.9, while Alpine and newer Ubuntu releases
ship 3.14.
2026-06-29 17:45:29 +02:00
Tobias Brunner b727eb88b4 github: Use AWS-LC 5.1.0 for tests
New version scheme (started after 1.73.0 with 4.0.0).
2026-06-29 17:45:29 +02:00
Tobias Brunner 7eefadca67 Use wolfSSL 5.9.2 for tests 2026-06-29 17:45:29 +02:00
Tobias Brunner 528898a976 unit-tests: Allow Ed448 implementations to fail parsing small-order public keys
We already adapted the Ed25519 test with 36b1a6d76c ("Use Botan 3.1.1
for tests"), now wolfSSL refuses to create such Ed448 keys as well.
2026-06-29 17:45:29 +02:00
Tobias Brunner 98b133c54c wolfssl: Adapt to removed ML-KEM header
The mlkem.h header that mainly defined aliases for the old wc_Kyber* API
has been removed and its contents moved to the wc_mlkem.h header.
2026-06-26 08:10:16 +02:00
Tobias Brunner ae7bb3bd42 github: Use OpenSSL 3.6.3 and 4.0.1 for tests 2026-06-09 13:54:06 +02:00
Andreas Steffen 5973ff8e41 Version bump to 6.0.7 2026-06-07 19:54:14 +02:00
Tobias Brunner d7e305f93f NEWS: Add news for 6.0.7 and info about CVE-2026-47895 2026-06-05 17:36:10 +02:00
R. Elliott Childre 075323d895 identification: Fix double-free when cloning empty IDs
The clone() method was missing a branch when there is an encoded chunk
of length 0 that still needed to be cloned.  Otherwise, the destruction
of the clone frees the same pointer that the original owns.

This double free was found with an improved `fuzz_ids` fuzz harness and
a two byte input to create an identification from "@#" or [0x40, 0x23].
It can also be triggered with `<type>:#` e.g. `dns:#`.

One of the problematic constructors is used to parse EAP-Identities,
which are cloned before storing them in the auth-cfg.   So this can be
triggered by an unauthenticated attacker.

Note that while the length check was already added with 418dbd6243
("cloning %any ID without zero-byte memleak") and identities that trigger
this can be created since 86ab5636c2 ("support for @#hex ID_KEY_ID
identification_t"), it was the referenced commit that made the length
check problematic.

Fixes: 2147da40a5 ("simplified identification_t.clone() using memcpy")
Fixes: CVE-2026-47895
2026-06-05 17:35:06 +02:00
Tobias Brunner 5fc403702b leak-detective: Also ignore unknown memory freed in OPENSSL_cleanup()
It seems that 18a94525a7 was a bit hasty.  Apparently, it's still the
case that there were reports (at least in some test scenarios).  Luckily,
the new facility added in the previous commit allows us to whitelist
these allocations without having to ignore all unknown memory.
2026-06-05 16:58:45 +02:00
Tobias Brunner 3216646bdb leak-detective: Add workaround for unknown memory reports with glibc
With glibc, there is an issue if TZ is not set, which causes a change
of the internally cached TZ value.  Because the original value was
cached before LD was active via `init_static_allocations()`, the memory
is freed as unknown memory later.  This change allows whitelisting
a function that might free such memory (tzset() only for now).
2026-06-05 16:40:49 +02:00
Tobias Brunner 4df53109a5 eap-aka: Make sure AT_RAND has the correct length in AKA-Challenge
This prevents an OOB read if the AT_RAND data is shorter than the
expected 16 bytes.

The check for AT_AUTN is changed for consistency even though its length
is already enforced by the parser (for AT_RAND it isn't because EAP-SIM
expects a length of either 32 or 48 bytes).

Fixes: aea334ec1c ("Splitted EAP-AKA in peer and server implementations, use libsimaka helper library")
2026-06-04 11:31:11 +02:00
Tobias Brunner a904f9125d kernel-netlink: Enable mixed-family IPComp scenarios
Since 6.3, the kernel allows setting XFRM_STATE_AF_UNSPEC for transport
mode SAs, which allows mixed-family use of IPComp.
2026-06-04 11:22:58 +02:00
Tobias Brunner 531de4d858 pkcs7: Fail parsing PKCS#7 signed-data if content can't be parsed
This avoids a crash after verifying the signed attributes in the signature
enumerator.
2026-06-01 18:21:43 +02:00
Tobias Brunner 74fd2593a7 charon-cmd: Make local host configurable
This allows preferring a particular address family (via 0.0.0.0 or ::)
or even a specific local address.
2026-06-01 09:03:02 +02:00
Tobias Brunner 64e01e2812 charon-cmd: Use %any as local address so IPv4 is not preferred
When resolving the remote host, we first determine if a particular
address family is preferred locally.  With `0.0.0.0` that's IPv4, with
`%any` that's not the case.  So we use the latter to allow resolvers
to return an IPv6 address.
2026-06-01 08:54:49 +02:00
Arthur ChanandTobias Brunner 615e7ad9ab oss-fuzz: Add new fuzzer targeting libtls
Closes strongswan/strongswan#3004

Signed-off-by: Arthur Chan <arthur.chan@adalogics.com>
Co-authored-by: Tobias Brunner <tobias@strongswan.org>
2026-05-29 15:30:42 +02:00
Tobias Brunner 5185b6f6e8 swanctl: Add option to only list a specific connection with --list-conns 2026-05-28 16:54:06 +02:00
Tobias Brunner 5b56e56e72 Merge branch 'vici-proposals'
Adds IKE and IPsec proposals to the `list-conn` VICI event.  Currently
not printed in `swanctl --list-conns` to keep the output compact (`--raw`
can be used to see the proposals).

Closes strongswan/strongswan#3067
2026-05-28 16:27:37 +02:00
Tobias Brunner b3ef007d28 vici: Return proposals in a more structured way
This allows clients to distinguish between algorithms of different
transform types more easily.  The names are similar to those used
when returning the algorithms of the selected proposal in list-sas (except
for `ke` instead of `dh` and `sn` instead of `esn` to reflect the
latest IETF/IANA changes).
2026-05-28 14:40:25 +02:00
Mathijs Smit c70ab88363 vici: Include proposals in connection listings
Signed-off-by: Mathijs Smit <smit.mathijs@gmail.com>
2026-05-28 14:40:25 +02:00
Tobias Brunner eb9e44f783 ike-cfg: Add flag to suppress log message when retrieving proposals 2026-05-28 14:40:25 +02:00
Tobias Brunner 60adb95f58 child-cfg: Add flag to suppress log message when retrieving proposals 2026-05-28 14:40:25 +02:00
Tobias Brunner bff405c349 oid: Fix confusing identifiers for elliptic curves over prime fields
SECT (indicating a binary field) was incorrectly used in constants for
the SECP (prime field) curves.
2026-05-28 13:30:07 +02:00
Tobias Brunner 5fcf1fc0ef public-key: Fix mapping of RSA with PKCS#1 v1.5 and SHA3-512 to OID
Fixes: 40f2589abf ("gmp: Support of SHA-3 RSA signatures")
2026-05-28 13:21:22 +02:00
Tobias Brunner 172c2a39d2 configure: Fix check for option that indicates if plugins are packaged separately
The option was renamed with 7f9f9bd375 ("Fixed some typos, courtesy of
codespell"), the check was not.

Fixes: dd7b0283ef ("plugin-loader: Add option to change log message if plugin is not found")
2026-05-28 12:34:12 +02:00
Tobias Brunner 96627b4af5 github: Fix typo when enabling curve25519 plugin for gcrypt tests
Doesn't make a difference as the configure script also accepts the option
with a single dash.
2026-05-28 12:33:24 +02:00
Tobias Brunner 6f99862da8 github: Move permissions to the individual jobs
SonarQube complains about workflow-level "allow" permissions.
2026-05-27 13:31:51 +02:00
Tobias Brunner 5a2ed87945 github: Increase the time CIFuzz is running the fuzzers
Several new fuzzers were added since this workflow was created (in
particular due to the plugin split).
2026-05-27 12:38:27 +02:00
Arthur Chan 50fc4c24a6 fuzz: Add fuzzer targeting RADIUS messages
Closes strongswan/strongswan#3027

Signed-off-by: Arthur Chan <arthur.chan@adalogics.com>
2026-05-27 12:36:26 +02:00
Arthur Chan a5bcaa70ed fuzz: Add fuzzer targeting VICI messages
Closes strongswan/strongswan#3026

Signed-off-by: Arthur Chan <arthur.chan@adalogics.com>
2026-05-27 12:32:40 +02:00
Tobias Brunner a76bd171f8 github: Add a note regarding vulnerability reports to issue template
Also updated the version numbers in the template.
2026-05-22 14:33:28 +02:00
Tobias Brunner dc8b479eb8 ike-init: Fix key derivation if SA is reset after IKE_INTERMEDIATE retransmits
Because the `derived` flag was not reset (it's set after the initial
IKE_SA_INIT exchange), no keys would get derived when sending
IKE_INTERMEDIATE during the next try.  As there is then no `aead_t`
available, encrypting the message would fail and the initiation would
remain stuck.

Fixes: 0d49ddec2e ("ike-init: Add support for multiple key exchanges")
2026-05-22 14:33:28 +02:00
Tobias Brunner 18a94525a7 Revert "testing: Ignore unknown memory in leak detective"
This reverts commit b998695344.

Seems like this is not necessary anymore.  Possibly because of
8ff3238027 ("openssl: Prevent OpenSSL from using posix_memalign() if
LD is enabled").
2026-05-22 14:33:28 +02:00
Thomas Jarosch f0a489f7e2 credential-manager: Check certificate expiry also for trusted self-signed certs
This serves as a defense-in-depth measure against forgotten
configs/credentials.
2026-05-22 14:33:28 +02:00
Thomas Jarosch 0d17838b99 credential-manager: Check expiry also for last cert in incomplete trust chain
While the validity of a pre-trusted certificate for which an issuer is
found is enforced via `check_certificate()`, the validity of such a
certificate in an incomplete trust chain, or rather that of the last
certificate in such a chain, was not enforced.  This fixes that
inconsistency.
2026-05-22 14:33:28 +02:00
Tobias Brunner 95f615a603 unit-tests: Replace expired self-signed TLS certificates 2026-05-22 14:33:28 +02:00
Tobias Brunner 9ac3db8e63 swid-gen: Use process_t to avoid potential command injection
In a targeted request, the software ID is provided by the IMV.  If no
database is used (which is not the recommended setup), the ID is not
validated and could potentially contain special characters.  With the
previous command string construction and use of popen(), which runs a
shell, that could potentially allow running arbitrary commands.
2026-05-19 17:27:33 +02:00
Tobias Brunner ac703e48c3 ike-init: Destroy KE object after each derivation during initial exchanges
This fixes error handling in build_r_multi_ke() so we don't incorrectly
reuse the object from the previous exchange if we don't receive a KE
payload.
2026-05-19 17:27:33 +02:00
Tobias Brunner 158b4c4aa4 child-rekey: Avoid potential use-after-free for deleted SPIs array 2026-05-19 17:27:33 +02:00
Tobias Brunner ea569867d2 tun-device: Fix setting IPv6 address on Linux
Unlike `struct ifreq` that's used for IPv4, `struct in6_ifreq` contains
not a `struct sockaddr[_in6]` but only a `struct in6_addr`.

Setting addresses like this is currently not used on Linux (the feature
was added to install virtual IPs on FreeBSD/macOS).

Fixes: fccc76449d ("tun-device: Fix handling of IPv6 addresses")
2026-05-19 17:27:33 +02:00
Tobias Brunner 7bdd4bf77b swanctl: Make sure options array passed to getopt_long() ends with a NULL entry 2026-05-19 17:27:33 +02:00
Tobias Brunner a1ad9e39fc pki: Make sure options array passed to getopt_long() ends with a NULL entry 2026-05-19 17:27:33 +02:00
Tobias Brunner 4950a37e56 pts: Fix error string if mandatory DH group is unavailable
Fixes: 0841280cdd ("libimcv: Fix build with DEBUG_LEVEL < 3")
2026-05-19 17:27:33 +02:00
Tobias Brunner 3b224a70ba xof: Fix mapping for SHA3-512 to a corresponding MGF1 identifier
Fixes: 3b7c49bc31 ("mgf1: Support of RSA PSS with SHA3 hash")
2026-05-19 17:27:33 +02:00
Tobias Brunner a26dd3da33 openssl: Check that EC keys don't have explicit params for internally loaded keys
Keys loaded via generic loader (KEY_ANY) or from a PKCS#12 file (or an
engine) don't go through the openssl_ec_private_key_load() constructor
that checks for explicit parameters.
2026-05-19 17:27:33 +02:00
Tobias Brunner ab19f691c7 botan: Fix registration of ECDSA signature/verification plugin features
This was broken since the Botan 3 release, which removed the EMSA1
class and the define.  The "EMSA1()" wrapper when signing/verifying is
technically not necessary anymore since then (it's deprecated but still
accepted).  But to still support Botan 2, we keep that in for now.
2026-05-19 17:27:33 +02:00
Tobias Brunner 15879eaddd github: Use AWS-LC 1.73.0 for tests 2026-05-19 17:27:33 +02:00
Tobias Brunner 7e7629499f receiver: Avoid unaligned memory access in COOKIE verification
This access could be an issue on platforms with strict alignment
requirements.
2026-05-19 17:27:33 +02:00