Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 42: rpki-client 9.7 Security Update FEDORA-2026-d2431d8ac0

fedora
Calendar Grey January 22, 2026
Dist Fedora Esm H88
The rpki-client 9.7 update for Fedora 42 introduces crucial changes for BGP origin validation and security stability.
rpki-client 9.7 The Canonical Cache Representation underwent a breaking change after the adoption of https://datatracker.ietf.org/doc/draft-ietf-sidrops-rpki-ccr/ as a SIDROPS work...

Summary

The OpenBSD rpki-client is a free, easy-to-use implementation of the

Resource Public Key Infrastructure (RPKI) for Relying Parties (RP) to

facilitate validation of the Route Origin of a BGP announcement. The

program queries the RPKI repository system, downloads and validates

Route Origin Authorisations (ROAs) and finally outputs Validated ROA

Payloads (VRPs) in the configuration format of OpenBGPD, BIRD, and

also as CSV or JSON objects for consumption by other routing stacks.

Update Information:

rpki-client 9.7 The Canonical Cache Representation underwent a breaking change after the adoption of https://datatracker.ietf.org/doc/draft-ietf-sidrops-rpki-ccr/ as a SIDROPS working group item. Apart from several CMS-related cosmetics it now uses a IANA-assigned content type. As a result, rpki-client 9.7 cannot parse rpki- client 9.6's .ccr files and vice versa. Support for Ghostbusters Record objects (RFC 6493) has been removed. Nobody showed interest in deploying this and there are other, widely supported ways of exchanging operational contact information such as RDAP. RFC 6493 is undergoing a status review to be marked as historic: https://datatracker.ietf.org/doc/status-change-rpki-ghostbusters-record-to- historic/ Prepare the code base for the opaque ASN1_STRING structure in OpenSSL 4. Fixed two reliability issues: one where a malicious RPKI Certification Authority can trigger a crash, one where malicious Trust Anchor can provoke memory exhaustion.

Change Log

* Tue Jan 13 2026 Robert Scheck 9.7-1 - Upgrade to 9.7 (#2429390)

References


[ 1 ] Bug #2429390 - rpki-client-9.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=2429390

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d2431d8ac0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rpki-client
Product: Fedora 42
Version: 9.7
Release: 1.fc42
Summary: OpenBSD RPKI validator to support BGP Origin Validation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here