---
schema: 1
kind: vulnerability
title: "CVE-2026-47895 — strongSwan: pre-auth double-free in libstrongswan identity cloning, unauthenticated RCE over EAP (patched 6.0.7)"
headline: "CVE-2026-47895 — strongSwan: pre-auth double-free in libstrongswan identity cloning, unauthenticated RCE over EAP (patched 6.0.7)"
summary: "The strongSwan project disclosed CVE-2026-47895 on 8 June (fixed in 6.0.7): a double-free in the clone() method of identification_t in libstrongswan, caused by checking encoded.len but not encoded.ptr (strongSwan, 2026-06-08.html))."
discovered_at: "2026-06-10T05:00:07Z"
event_date: 2026-06-09
run_id: 2026-06-10-c84347b2
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - rce
regions:
  - switzerland
  - europe
  - global
sectors:
  - public-sector
entities: []
cves:
  - id: CVE-2026-47895
    cvss: n/a
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://www.strongswan.org/blog/2026/06/08/strongswan-vulnerability-(cve-2026-47895"
    publisher: "strongSwan, 2026-06-08"
    role: primary
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1832"
    publisher: "BSI CERT-Bund, 2026-06-09"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-10.md
---

The strongSwan project disclosed CVE-2026-47895 on 8 June (fixed in 6.0.7): a double-free in the `clone()` method of `identification_t` in libstrongswan, caused by checking `encoded.len` but not `encoded.ptr` ([strongSwan, 2026-06-08](https://www.strongswan.org/blog/2026/06/08/strongswan-vulnerability-(cve-2026-47895).html)). An identity with empty-but-non-NULL binary encoding (e.g. `chunk_from_hex()` on empty input) makes the original and clone point to the same heap allocation; on glibc — which always returns a unique non-NULL pointer for zero-length `malloc()` — the double-free fires reliably. The exploitable path is the EAP-Identity exchange: the server clones and stores the supplied identity, and when authentication fails the IKE SA teardown triggers the free, making this reachable pre-authentication against any strongSwan IKEv2 server with EAP enabled (EAP-Identity, EAP-TTLS sub-identity, XAuth `xauth-eap`). All versions since 4.3.3 are affected; BSI published WID-SEC-2026-1832 ([BSI CERT-Bund, 2026-06-09](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1832)). strongSwan is the canonical Linux IPsec/IKEv2 stack (ETH Zurich lineage) across CH/EU VPN infrastructure. No public PoC or ITW exploitation reported; upgrade to 6.0.7, or temporarily require certificate-only auth.
