CVE-2024-45238
published 2024-08-24CVE-2024-45238: An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.30%
22.9th percentile
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. OpenSSL does not report this problem during parsing, and when compiled with OpenSSL libcrypto versions below 3, Fort recklessly dereferences the pointer. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fort-validator | < fort-validator 1.5.4-1+deb12u1 (bookworm) | fort-validator 1.5.4-1+deb12u1 (bookworm) |
| nicmx | fort-validator | >= 0 < 1.5.3-1~deb11u2 | 1.5.3-1~deb11u2 |
| nicmx | fort-validator | >= 0 < 1.5.4-1+deb12u1 | 1.5.4-1+deb12u1 |
| nicmx | fort-validator | >= 0 < 1.6.3-1 | 1.6.3-1 |
| nicmx | fort-validator | >= 0 < 1.6.3-1 | 1.6.3-1 |
| nicmx | fort-validator | >= 0 < 1.5.3-1ubuntu0.1 | 1.5.3-1ubuntu0.1 |
| nicmx | fort-validator | >= 0 < 1.2.0-1ubuntu0.1~esm1 | 1.2.0-1ubuntu0.1~esm1 |
| nicmx | fort-validator | >= 0 < 1.6.1-1ubuntu0.1~esm2 | 1.6.1-1ubuntu0.1~esm2 |
| nicmx | fort_validator | < 1.6.3 | 1.6.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FORT Validator vulnerabilities
vendor_ubuntu·2025-10-08·CVSS 7.5
CVE-2024-45236 [HIGH] FORT Validator vulnerabilities
Title: FORT Validator vulnerabilities
Summary: Several security issues were fixed in FORT Validator.
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing certain RPKI repository data.
A remote attacker could possibly use this issue to cause FORT Validator to
crash, resulting in a denial of service. (CVE-2024-45234, CVE-2024-45235,
CVE-2024-45236, CVE-2024-45238, CVE-2024-45239)
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing resource certificates. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2024-45237)
Koen van Hove discovered that FORT Validator did not limit the duration of
data transfers wh
Debian
CVE-2024-45238: fort-validator - An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that d...
vendor_debian·2024·CVSS 7.5
CVE-2024-45238 [HIGH] CVE-2024-45238: fort-validator - An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that d...
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. OpenSSL does not report this problem during parsing, and when compiled with OpenSSL libcrypto versions below 3, Fort recklessly dereferences the pointer. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.
Scope: local
bookworm: resolved (fixed in 1.5.4-1+deb12u1)
bullseye: resolved (fixed in 1.5.3-1~deb11u2)
forky: resolved (fixed in 1.6.3-1)
sid: resolved (fixed in 1.6.3-1)
trixie: resolved (fixed in 1.6.3-1)
OSV
fort-validator vulnerabilities
osv·2025-10-08·CVSS 7.5
CVE-2024-45234 [HIGH] fort-validator vulnerabilities
fort-validator vulnerabilities
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing certain RPKI repository data.
A remote attacker could possibly use this issue to cause FORT Validator to
crash, resulting in a denial of service. (CVE-2024-45234, CVE-2024-45235,
CVE-2024-45236, CVE-2024-45238, CVE-2024-45239)
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing resource certificates. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2024-45237)
Koen van Hove discovered that FORT Validator did not limit the duration of
data transfers when fetching RPKI repository data. A remote attacker could
possibly use
GHSA
GHSA-5mgq-44p6-x2pr: An issue was discovered in Fort before 1
ghsa_unreviewed·2024-08-25
CVE-2024-45238 [HIGH] CWE-476 GHSA-5mgq-44p6-x2pr: An issue was discovered in Fort before 1
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. OpenSSL does not report this problem during parsing, and when compiled with OpenSSL libcrypto versions below 3, Fort recklessly dereferences the pointer. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.
OSV
CVE-2024-45238: An issue was discovered in Fort before 1
osv·2024-08-24·CVSS 7.5
CVE-2024-45238 [HIGH] CVE-2024-45238: An issue was discovered in Fort before 1
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. OpenSSL does not report this problem during parsing, and when compiled with OpenSSL libcrypto versions below 3, Fort recklessly dereferences the pointer. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-24
Published