The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
https://www.strongswan.org/blog/2021/10/18/strongswan-vulnerability-%28cve-2021-41990%29.html
https://www.debian.org/security/2021/dsa-4989
https://github.com/strongswan/strongswan/releases/tag/5.9.4
https://cert-portal.siemens.com/productcert/pdf/ssa-539476.pdf