CVE-2021-3761

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3761
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3761.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3761
Aliases
Related
Published
2021-09-09T14:15:09Z
Modified
2024-09-18T03:15:35.845601Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Cloudflare) prior to launching a BGP hijack which during normal operations would be rejected as "RPKI invalid". Additionally, in certain deployments RTR session flapping in and of itself also could cause BGP routing churn, causing availability issues.

References

Affected packages

Debian:11 / cfrpki

Package

Name
cfrpki
Purl
pkg:deb/debian/cfrpki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.2-1~deb11u1

Affected versions

1.*

1.2.2-1
1.3.0-1
1.4.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / cfrpki

Package

Name
cfrpki
Purl
pkg:deb/debian/cfrpki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/cloudflare/cfrpki

Affected ranges

Type
GIT
Repo
https://github.com/cloudflare/cfrpki
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

v1.*

v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2.0
v1.2.0-pre
v1.2.1
v1.2.2