CVE-2024-56375
published 2024-12-22CVE-2024-56375: An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.45%
37.0th percentile
An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList. Fort dereferences (and, shortly afterwards, writes to) this array during a shuffle attempt, before the validation that would normally reject it when empty. This out-of-bounds access is caused by an integer underflow that causes the surrounding loop to iterate infinitely. Because the product is permanently stuck attempting to overshuffle an array that doesn't actually exist, a crash is nearly guaranteed.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fort-validator | < fort-validator 1.6.5-1 (forky) | fort-validator 1.6.5-1 (forky) |
| nicmx | fort-validator | >= 0 < 1.6.5-1 | 1.6.5-1 |
| nicmx | fort-validator | >= 0 < 1.6.5-1 | 1.6.5-1 |
| nicmx | fort-validator | >= 1.6.3 < 1.6.5 | 1.6.5 |
| nicmx | fort_validator | — | — |
| nicmx | fort_validator | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-533g-7w58-g89m: An integer underflow was discovered in Fort 1
ghsa_unreviewed·2024-12-23
CVE-2024-56375 [HIGH] CWE-191 GHSA-533g-7w58-g89m: An integer underflow was discovered in Fort 1
An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList. Fort dereferences (and, shortly afterwards, writes to) this array during a shuffle attempt, before the validation that would normally reject it when empty. This out-of-bounds access is caused by an integer underflow that causes the surrounding loop to iterate infinitely. Because the product is permanently stuck attempting to overshuffle an array that doesn't actually exist, a crash is nearly guaranteed.
OSV
CVE-2024-56375: An integer underflow was discovered in Fort 1
osv·2024-12-22·CVSS 7.5
CVE-2024-56375 [HIGH] CVE-2024-56375: An integer underflow was discovered in Fort 1
An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList. Fort dereferences (and, shortly afterwards, writes to) this array during a shuffle attempt, before the validation that would normally reject it when empty. This out-of-bounds access is caused by an integer underflow that causes the surrounding loop to iterate infinitely. Because the product is permanently stuck attempting to overshuffle an array that doesn't actually exist, a crash is nearly guaranteed.
Debian
CVE-2024-56375: fort-validator - An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A mali...
vendor_debian·2024·CVSS 7.5
CVE-2024-56375 [HIGH] CVE-2024-56375: fort-validator - An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A mali...
An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList. Fort dereferences (and, shortly afterwards, writes to) this array during a shuffle attempt, before the validation that would normally reject it when empty. This out-of-bounds access is caused by an integer underflow that causes the surrounding loop to iterate infinitely. Because the product is permanently stuck attempting to overshuffle an array that doesn't actually exist, a crash is nearly guaranteed.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.6.5-1)
sid: resolved (fixed in 1.6.5-1)
trixie: resolved (fixed in 1.6.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-22
Published