First published: Thu Nov 11 2021(Updated: )
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
Credit: cna@cloudflare.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/cfrpki | 1.4.2-1~deb11u1 1.4.4-1 1.5.10-2 | |
Cloudflare Octorpki | <1.3.0 | |
Debian Debian Linux | =11.0 |
Upgrade to 1.4
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3911 is medium with a CVSSv3 score of 6.5.
CVE-2021-3911 can cause OctoRPKI to crash if the ROA returned by a repository contains too many bits for the IP address.
The affected software versions are cfrpki 1.4.2-1~deb11u1, 1.4.4-1, 1.5.10-2 for Debian and Octorpki up to version 1.3.0 for Cloudflare.
To fix CVE-2021-3911 in Debian, update the cfrpki package to version 1.4.2-1~deb11u1, 1.4.4-1, or 1.5.10-2.
More information about CVE-2021-3911 can be found on the GitHub security advisory and Debian security tracker pages.