PT-2021-23320 · Nlnet · Nlnet Labs Routinator

Job Snijders

·

Published

2021-09-21

·

Updated

2021-10-05

·

CVE-2021-41531

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions NLnet Labs Routinator versions prior to 0.10.0
Description The issue arises when an RPKI CA uses excessively large values in the max-length parameter within a ROA, causing NLnet Labs Routinator to produce an invalid RTR payload. This results in RTR clients, such as routers, rejecting the RPKI data set, which effectively disables Route Origin Validation.
Recommendations For versions prior to 0.10.0, update to version 0.10.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of large values in the max-length parameter in ROAs to prevent the production of invalid RTR payloads until a patch is applied.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41531

Affected Products

Nlnet Labs Routinator