CVE-2021-3761High· 7.5▾ TwilightOctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.2%
Any CA issuer in the RPKI can trick OctoRPKI prior to https://github.com/cloudflare/cfrpki/commit/a8db4e009ef217484598ba1fd1c595b54e0f6422 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate.
An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Cloudflare) prior to launching a BGP hijack which during normal operations would be rejected as "RPKI invalid". Additionally, in certain deployments RTR session flapping in and of itself also could cause BGP routing churn, causing availability issues.
https://github.com/cloudflare/cfrpki/commit/a8db4e009ef217484598ba1fd1c595b54e0f6422
https://github.com/cloudflare/cfrpki/releases/tag/v1.3.0
If you have any questions or comments about this advisory:
github.com/cloudflare/cfrpki < 1.3.0Upgrade to a patched release:
github.com/cloudflare/cfrpki 1.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-3912Medium· 4.2OctoRPKI crashes when processing GZIP bomb returned via malicious repository
CVE-2021-3911Medium· 4.2Misconfigured IP address field in ROA leads to OctoRPKI crash
CVE-2021-3908Medium· 5.9Infinite certificate chain depth results in OctoRPKI running forever
CVE-2021-3909Medium· 4.4Infinite open connection causes OctoRPKI to hang forever
CVE-2021-3910High· 7.5NUL character in ROA causes OctoRPKI to crash
CVE-2022-3616Medium· 5.4OctoRPKI crashes when max iterations is reached