Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 40: rpki-client 9.5 critical: denial of service fix

fedora
Calendar Grey April 21, 2025
Dist Fedora Esm H88
Fedora 40 rolls out OpenSSL 3.1, fortifying cryptographic functions and addressing a significant vulnerability identified in earlier releases.
rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered

Summary

The OpenBSD rpki-client is a free, easy-to-use implementation of the

Resource Public Key Infrastructure (RPKI) for Relying Parties (RP) to

facilitate validation of the Route Origin of a BGP announcement. The

program queries the RPKI repository system, downloads and validates

Route Origin Authorisations (ROAs) and finally outputs Validated ROA

Payloads (VRPs) in the configuration format of OpenBGPD, BIRD, and

also as CSV or JSON objects for consumption by other routing stacks.

Update Information:

rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered. See https://www.arin.net/announcements/20250116-tal/ rpki-client reports Certification Authorities that do not meaningfully participate in the RPKI as non-functional CAs. By definition, a CA is non- functional if there is no currently valid Manifest. The number of such CAs is printed at the end of each run and more detailed information is available in the JSON (-j) and ometrics (-m) output. OpenBSD reliability errata 014: Incorrect internal RRDP state handling in rpki- client can lead to a denial of service. Affected are rpki-client versions 7.5 - 9.4. Termination of rsync child processes with SIGTERM is no longer treated as an error if rpki-client has sent this signal. This only affects openrsync. Do not exit filemode with an error if a .gbr or a .tak object contains control characters in its UTF-8 strings. Instead, only warn and emit a sanitized version in JSON output. Upcoming...

Change Log

* Sat Apr 12 2025 Robert Scheck 9.5-1 - Upgrade to 9.5 (#2359198) * Sat Jan 18 2025 Fedora Release Engineering - 9.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild

References


[ 1 ] Bug #2359198 - rpki-client-9.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2359198

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d5fdbedb7f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rpki-client
Product: Fedora 40
Version: 9.5
Release: 1.fc40
Summary: OpenBSD RPKI validator to support BGP Origin Validation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here