CVE-2021-3911: Misconfigured IP address field in ROA leads to OctoRPKI crash
Published Nov 11, 2021
·Updated
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
Affected Software
3 affected componentsFixes available
debian/cfrpki
1.4.2-1~deb11u11.4.4-11.5.10-2
Cloudflare OctoRPKI<1.3.0
Debian Debian Linux=11.0
Remediation
Information
Upgrade to 1.4
Event History
Nov 11, 2021
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-3911?
The severity of CVE-2021-3911 is medium with a CVSSv3 score of 6.5.
2
How does CVE-2021-3911 impact OctoRPKI?
CVE-2021-3911 can cause OctoRPKI to crash if the ROA returned by a repository contains too many bits for the IP address.
3
Which software versions are affected by CVE-2021-3911?
The affected software versions are cfrpki 1.4.2-1~deb11u1, 1.4.4-1, 1.5.10-2 for Debian and Octorpki up to version 1.3.0 for Cloudflare.
4
How can I fix CVE-2021-3911 in Debian?
To fix CVE-2021-3911 in Debian, update the cfrpki package to version 1.4.2-1~deb11u1, 1.4.4-1, or 1.5.10-2.
5
Where can I find more information about CVE-2021-3911?
More information about CVE-2021-3911 can be found on the GitHub security advisory and Debian security tracker pages.