OctoRPKI crashes when a repository returns an ROA with a IP address that contains too many bits.
{
"url": "https://pkg.go.dev/vuln/GO-2022-0252",
"review_status": "REVIEWED"
}{
"imports": [
{
"symbols": [
"DecodeROA",
"DecoderConfig.DecodeROA",
"GetRangeIP",
"IPNet.GetRange",
"RPKICertificate.ValidateIPCertificate",
"RPKIROA.ValidateIPRoaCertificate",
"ValidateIPCertificateList",
"ValidateIPRoaCertificateList"
],
"path": "github.com/cloudflare/cfrpki/validator/lib"
}
]
}