Commit Graph
19780 Commits
Author SHA1 Message Date
Lukas Johannes Möller aa5aaebc33 libsimaka: Reject zero-length EAP-SIM/AKA attributes
parse_attributes() accepts hdr->length == 0 in the AT_ENCR_DATA,
AT_RAND, AT_PADDING, default branches. The code then subtracts the
fixed attribute header size from the encoded length, which underflows
and exposes a wrapped payload length to later code.  In particular,
for the cases where add_attribute() is called, this causes a heap-based
buffer overflow (a buffer of 12 bytes is allocated to which the wrapped
length is written).  For AT_PADDING, the underflow is irrelevant as
add_attribute() is not called. Instead, this results in an infinite loop.

Reject zero-length attributes before subtracting the attribute header.

Signed-off-by: Lukas Johannes Möller <research@johannes-moeller.dev>

Fixes: f8330d0395 ("Added a libsimaka library with shared message handling code for EAP-SIM/AKA")
Fixes: CVE-2026-35330
2026-04-21 16:48:56 +02:00
Tobias Brunner 19d73ef156 github: Move CI for Windows from AppVeyor to GitHub Actions
These are quite a bit faster than on AppVeyor (with ccache about a fifth,
without less than half - and they run concurrently).

We only keep the AppVeyor builds for now to test against those old
OpenSSL versions (1.1.1 and 1.0.2) for which there is still extended
support available.  Even simplified like that they still take longer
than the builds on GA.
2026-04-21 16:44:18 +02:00
Tobias Brunner e0fb06c9cc Revert "github: Remove commit ID from cache keys"
Without commit ID, no new caches are created as the key is always the
same.

This reverts commit 60f4c86780.
2026-04-21 11:05:19 +02:00
Tobias Brunner 60f4c86780 github: Remove commit ID from cache keys
This reduces the cache storage for active branches and since caches for
different branches are separate and we abort previous builds of the same
branch, this is not necessary to ensure caches can successfully be stored.
2026-04-17 15:18:11 +02:00
Tobias Brunner 1d36cae26a cirrus/github: Move CI for Alpine from Cirrus CI to GitHub Actions
Same as the previous commit.
2026-04-17 14:38:14 +02:00
Tobias Brunner 06b14b8988 cirrus/github: Move CI for FreeBSD from Cirrus CI to GitHub Actions
Cirrus CI will shut down in June, so we have to find a replacement to
test our build on FreeBSD.  This uses VMs on GitHub Actions.
2026-04-17 10:36:36 +02:00
Tobias Brunner cb27593ce0 kernel-netlink: Update family in SA selector if addresses change 2026-04-16 15:33:25 +02:00
Tobias Brunner e1a11e2c1c ike: Use correct format string for unique Child SA identifiers
Analogous to the previous commit.
2026-04-16 15:32:54 +02:00
Tobias Brunner 2a8fd3e4bf ike: Use correct format string for unique IKE SA identifiers
Would take a while until it became an issue, though.
2026-04-16 15:32:54 +02:00
Tobias Brunner 5334d93a45 delete-ike-sa-job: Log unique ID when deleting half-open IKE SA 2026-04-16 15:32:54 +02:00
Tobias Brunner 7f6fc50ba3 ike-init: Log the IKE SA's unique identifier when creating one as responder
The name will not be defined yet, but we have a similar message as
initiator so use the same format.
2026-04-16 15:32:54 +02:00
Tobias Brunner 1ee7e10940 testing: Fix typo regarding ML-KEM in description 2026-04-15 15:01:40 +02:00
Tobias Brunner 7862974e10 github: Use AWS-LC 1.72.0 for tests 2026-04-14 08:33:56 +02:00
Markus Theil c60a14ba23 botan: Fix typo in algorithm string for SHA3-224 RSA verification
Signed-off-by: Markus Theil <markus.theil@secunet.com>
2026-04-13 15:46:45 +02:00
Markus Theil e1091327b5 tun-device: Also close IPv6 socket on destruction
Signed-off-by: Markus Theil <markus.theil@secunet.com>
2026-04-13 15:13:14 +02:00
Markus Theil febe474926 encrypted-payload: Check for non-zero payload size
Signed-off-by: Markus Theil <markus.theil@secunet.com>
2026-04-13 15:12:55 +02:00
Markus Theil fdd06d99ec botan: Make RNG types configurable
This allows for usage of ESDM or jitterentropy as Botan RNG without
patching strongSwan.

Signed-off-by: Markus Theil <markus.theil@secunet.com>
2026-04-13 15:12:31 +02:00
Tobias Brunner 0d4a8cc9ba appveyor: Reduce build time and remove build against OpenSSL 1.1.0
We are still too close to the limit of 1 hour (at least with the 2019
image and the 2022 image is about the same), so reduce the build time by
not building libimcv natively, which saves about 10 minutes.

Also, only build against OpenSSL 1.0.2 (on the 2017 image) and 1.1.1 (on
the 2019 image) as these are the only versions for which OpenSSL provides
extended support.
2026-04-13 15:08:47 +02:00
Tobias Brunner 032d8adcd4 github: Continue crypto tests even if OpenSSL tests fail
These can sometimes fail because of sync issues with Ubuntu debug symbol
packages, let other crypto tests continue.
2026-04-09 09:53:36 +02:00
Tobias Brunner e8e34c4b33 Use wolfSSL 5.9.1 for tests 2026-04-09 09:53:36 +02:00
Tobias Brunner 99e9db478d unit-tests: Use longer input for ECDSA tests
wolfSSL 5.9.1 starts to enforce a minimum (and maximum) length for the
hash when signing.  Since we'll always require SHA-1, use 20 bytes as
input in the tests to succeed with SIGN_ECDSA_WITH_NULL.
2026-04-09 09:53:36 +02:00
Tobias Brunner b9d9f8ad95 fuzz: Remove unnecessary calls to set plugin dirs
All the plugins are linked statically into the binaries, so there
is no reason to set the directories that are only required when loading
them from files.
2026-04-08 15:57:17 +02:00
Tobias Brunner 444a1dc0e3 fuzz: Create fuzzers with default and custom crypto plugins
The pa_tnc fuzzer does not rely on any plugins and the pb_tnc fuzzer is
a bit special in that it does use code from the tnccs-20 plugin, but that
doesn't actually have to be loaded as such. The fuzzer directly calls
statically linked code from the plugin.
2026-04-08 15:56:42 +02:00
Tobias Brunner 521c6e05c5 github: Update actions so they don't use deprecated Node.js 20 2026-04-07 18:57:40 +02:00
Tobias Brunner b56b3d48b6 tls-server: Avoid allocating large buffer for cipher suites on stack
The `cipher_suites` field has a 16-bit length field, so up to 32k 2-byte
cipher suites could technically be proposed.  With `tls_cipher_suite_t`
typically being 4 bytes wide, the necessary allocation for the temporary
array can be up to 128 KiB.  Even though this should be fine on typical
systems, we avoid potentially overflowing the stack by using malloc()
instead of alloca().
2026-04-02 08:34:23 +02:00
Tobias Brunner a3c5fad1ff libipsec: Reject policies for anything but ESP tunnel mode
This is only relevant for trap policies as similar SAs are already
rejected when negotiated.
2026-04-02 08:34:20 +02:00
Tobias Brunner 2a63343968 trap-manager: Ignore acquires without selectors for wildcard traps
We need to know the actual destination address to process these.
2026-04-02 08:33:30 +02:00
Tobias Brunner 66fffdb1bf ike-init: Remove redundant check for more key exchanges during rekeying
We only call derive_keys() after a successful key_exchange_done() call
during rekeying, so this will always return FALSE.
2026-04-02 08:17:05 +02:00
Tobias Brunner 05807b1b1b openssl: Handle EdDSA keys from engines special again
Fixes: 052a939553 ("openssl: Add support for Ed25519 via AWS-LC")
2026-04-02 08:17:05 +02:00
Tobias Brunner 4af485d87d certreq: Avoid OOB read when enumerating hashes in OCSP CERTREQ
These certificate requests also contain SHA-1 hashes, which is assumed
in `ike_cert_pre.c::process_certreq()` when enumerating key IDs.

Because the parser allocates a separate chunk for the data and the
enumerator doesn't read beyond that chunk's length after the first
iteration, only lengths between 1 and 19 are problematic (0 doesn't
cause an enumeration because chunk_empty is assigned).

Whether the OOB read then can cause a segmentation fault depends on the
allocator, its alignment rules, and its minimum overhead.  For instance,
with glibc on a typical 64-bit system (8 bytes for pointers and size_t),
the alignment is 16 bytes and the minimum allocated size is 32 bytes,
with typically 24 that are technically available for data, even if only
0 bytes are allocated (as returned by `malloc_usable_size()`).  So with
an allocation between 1 and 19, we can always safely read 20 bytes.

Assuming that other allocators behave similar for small allocations, it
seems unlikely that this causes a crash.

Fixes: 15612b3a42 ("Add support for IKEv2 OCSP extensions (RFC 4806)")
2026-04-02 08:17:05 +02:00
Tobias Brunner 20b07f2cbf vici: Prevent uninitialized memory access if VICI_LIST_ITEM is too short
If there is only a single length byte, `value` is not changed and points
to uninitialized data.
2026-04-02 08:17:05 +02:00
Tobias Brunner 513f25ce12 tnccs_11: Avoid crash if TNCCS-ReasonStrings is empty or only contains empty nodes
`xmlNodeGetContent()` returns `NULL` if `child` is `NULL`, which causes
a segmentation fault in `chunk_from_str()`.

Fixes: ec1eab0319 ("fixed XML parsing of TNCCS 1.1 ReasonString message")
2026-04-02 08:17:05 +02:00
Tobias Brunner 65fcf08cdb eap-sim: Prevent infinite loop if version list contains more than one entry
Fixes: ac4dd5439b ("Migrated EAP-SIM to libsimaka, separated server/peer implementations")
2026-04-02 08:17:04 +02:00
Tobias Brunner 7b0190cb26 revocation: Fix memory leak if nonce in OCSP response doesn't match 2026-04-02 08:17:04 +02:00
Tobias Brunner 1e1dd2976d message: Drop fragments with total fragment count lower than before
The RFC only allows that the number of fragments increases (if the
sender reduces the MTU).

Not enforcing this before could cause early reassembly as the trigger was
that the number of received fragments matches the total count of the
current packet (which was a bit weird anyway).  Only an active MITM could
trigger this as individual fragments are encrypted and authenticated.
2026-04-02 08:17:04 +02:00
Tobias Brunner 06e5462a4b credential-factory: Enforce an upper limit when creating nested credentials
This mainly intended as defense-in-depth measure to avoid parsing
massively nested structures that could cause a call stack overflow due
to the massive recursion.  In particular PKCS#7 signed data is prone to
this as these can be nested basically infinitely.  When used in IKEv1 via
ENC_PKCS7_WRAPPED_X509 CERT payloads, our default of 10000 bytes for IKE
messages guards against this, but that's configurable and there might be
a chance for some bug that triggers problematic recursive parsing for
smaller input.

The upper limit is chosen arbitrarily, but there are currently no known
cases that require a depth of more than 10 levels.
2026-04-02 08:16:07 +02:00
Tobias Brunner 236ef93c50 tls-peer: Ensure TLS 1.3 CertificateRequest structure is valid
If nothing was read from the message, the previous code could result in
a crash depending on where `ext.ptr` pointed to, as determined by the
current stack contents.  Since TLS 1.3 is still disabled by default and
this is usually used for TLS-based EAP methods after validating the
IKEv2 server's certificate, the real world impact seems relatively low.

Fixes: 9ef46cfaf9 ("tls-peer: Mutual authentication support for TLS 1.3")
2026-04-02 08:14:29 +02:00
Tobias Brunner e454b4adb3 libsimaka: Prevent out-of-bounds read when parsing attributes with actual length field
These attributes contain a 16-bit length field for the actual length of
the data in bits or bytes, as compared to the length in 4-byte blocks in
the attribute header.  The previous code didn't correctly account for the
length of the fixed header (4 bytes) when it compared the parsed length
to the length in the header.  This could cause an out-of-bounds read of
up to four bytes beyond the end of the attribute/message.

Fixes: f8330d0395 ("Added a libsimaka library with shared message handling code for EAP-SIM/AKA")
2026-04-02 08:14:29 +02:00
Tobias Brunner 0b053e048d nm: Ignore all .gmo files 2026-04-02 07:54:04 +02:00
Tobias Brunner b377a41336 dhcp: Use correct getter for boolean force_server_address option 2026-04-01 19:33:09 +02:00
Tobias Brunner 3c637c7521 openssl: Fix return value if returning EdDSA public key fails 2026-04-01 19:33:09 +02:00
Tobias Brunner 440b7e7940 Use Botan 3.11.1 for tests 2026-04-01 19:33:09 +02:00
Ekaterine Papava 988d777ebb nm: Add Georgian translation
Closes strongswan/strongswan#3041

Signed-off-by: Ekaterine Papava <papava.e@gtu.ge>
2026-04-01 19:31:33 +02:00
Andreas Steffen 1fdcd5b0d3 Ignore tarball checksums and signatures 2026-03-23 17:24:53 +01:00
Andreas Steffen 62f5d17c12 Version bump to 6.0.5 2026-03-23 13:41:52 +01:00
Tobias Brunner 01908d59b0 NEWS: Add info about CVE-2026-25075 2026-03-20 16:28:20 +01:00
Tobias Brunner 73aff21077 eap-ttls: Prevent crash if AVP length header field is invalid
The length field in the AVP header includes the 8 bytes of the header
itself.  Not checking for that and later subtracting it causes an
integer underflow that usually triggers a crash when accessing a
NULL pointer that resulted from the failing chunk_alloc() call because
of the high value.

The attempted allocations for invalid lengths (0-7) are 0xfffffff8,
0xfffffffc, or 0x100000000 (0 on 32-bit hosts), so this doesn't result
in a buffer overflow even if the allocation succeeds.

Fixes: 79f2102cb4 ("implemented server side support for EAP-TTLS")
Fixes: CVE-2026-25075
2026-03-19 16:49:41 +01:00
Tobias Brunner 0fcece9fff Use wolfSSL 5.9.0 for tests 2026-03-19 09:18:08 +01:00
Tobias Brunner b23387a3d6 conf: Install charon-specific snippets also when charon itself is not built
To make the default strongswan.conf, with `load_modular` enabled, work
if charon itself is not built, we enable generating the charon-specific
snippets also for the two other daemons that fall back on reading
options from the `charon` section.
2026-03-17 08:32:34 +01:00
Tobias Brunner 0d10fa6dda conf: Generate and install config snippets also for charon-cmd and charon-nm
This allows easier customization for distributions (e.g. disable some
plugins by default).
2026-03-17 08:08:38 +01:00