PT-2024-31493 · Fort+3 · Fort+3

·

CVE-2024-45235

·

Published

2024-08-24

·

Updated

2025-10-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Fort versions prior to 1.6.3
Description An issue was discovered in Fort where a malicious RPKI repository that descends from a trusted Trust Anchor can serve a resource certificate containing an Authority Key Identifier extension that lacks the keyIdentifier field. Fort references this pointer without sanitizing it first, which can lead to a crash and make Route Origin Validation unavailable, resulting in compromised routing.
Recommendations For versions prior to 1.6.3, update to version 1.6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the RPKI repository to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45235
DLA-4066-1
USN-7813-1

Affected Products

Debian
Fort
Linuxmint
Ubuntu