Earlier quoted context omitted.
The relatively benign legacy kernel level pointer-bug CVE chosen is hardly the worst thing from WireGuard or strongSwan over the years. However, it makes the point a priority reliable network side-channel administrative login is more robust under some use-cases. Adding layers of complexity rarely improves security, and doesn't usually address the underlying issue of accountability. And I often ponder if a bastion hos…
The bug you cited is in Netlink . It's not exposed on the network. What's the "worse" thing you're referring to? I think you just searched "WireGuard CVE" and tried to play it off.
https://www.cve.org/CVERecord/SearchResults?query=ipsec
https://www.cve.org/CVERecord/SearchResults?query=wireguard
https://www.cve.org/CVERecord/SearchResults?query=strongswan
Best of luck, and straw-man arguments are never taken seriously. =3