CVE-2021-3910: NUL character in ROA causes OctoRPKI to crash
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-3910?
CVE-2021-3910 is a vulnerability that affects OctoRPKI and Debian Linux, allowing a specially crafted repository to cause a crash by returning an invalid ROA.
What is the severity of CVE-2021-3910?
CVE-2021-3910 has a severity of 7.5 (high).
Which software is affected by CVE-2021-3910?
OctoRPKI versions 1.3.0 and earlier, as well as Debian Linux 11.0, are affected by CVE-2021-3910.
How can I fix CVE-2021-3910?
To fix CVE-2021-3910, update OctoRPKI to version 1.4.2-1~deb11u1, 1.4.4-1, or 1.5.10-2, or update Debian Linux to the latest version.
Where can I find more information about CVE-2021-3910?
For more information about CVE-2021-3910, you can refer to the following sources: [GitHub Advisory](https://github.com/cloudflare/cfrpki/security/advisories/GHSA-5mxh-2qfv-4g7j), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2021-3910), [Debian Security Advisory](https://www.debian.org/security/2022/dsa-5041)