Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 43 rpki-client 9.8 Critical Update DoS Risk 2026-27892c9184

fedora
Calendar Grey April 24, 2026
Dist Fedora Esm H88
Discover the latest Fedora 43 rpki-client update and its enhancements for BGP Origin Validation. Stay secure with this vital fix.
rpki-client 9.8 Various refactoring for improved compatibility with various libcrypto implementations and in CA/BGPsec certificate handling

Summary

The OpenBSD rpki-client is a free, easy-to-use implementation of the

Resource Public Key Infrastructure (RPKI) for Relying Parties (RP) to

facilitate validation of the Route Origin of a BGP announcement. The

program queries the RPKI repository system, downloads and validates

Route Origin Authorisations (ROAs) and finally outputs Validated ROA

Payloads (VRPs) in the configuration format of OpenBGPD, BIRD, and

also as CSV or JSON objects for consumption by other routing stacks.

Update Information:

rpki-client 9.8 Various refactoring for improved compatibility with various libcrypto implementations and in CA/BGPsec certificate handling. Fixed an accounting issue in HTTP gzip compression detection. Added a warning in extra verbose mode (-vv) about standards non-compliant Issuer and Subject ASN.1 string encodings. Added a check for canonical encoding of ASPA eContent in alignment with draft- ietf-sidrops-aspa-profile-22. Ensure that a repository timeout correctly stops repository processing. Fixed a defect in Canonical Cache Representation ROAIPAddressFamily sort order. As a result, rpki-client 9.8 cannot parse rpki-client 9.7's .ccr files and vice versa. Fixed an issue in the parser for the locally configured constraints. A malicious RRDP Publication Server can cause a NULL dereference. A malicious RPKI Publication Server can cause an incorrect error exit.

Change Log

* Thu Apr 16 2026 Robert Scheck 9.8-1 - Upgrade to 9.8 (#2458536) * Sat Jan 17 2026 Fedora Release Engineering - 9.7-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References


[ 1 ] Bug #2458536 - rpki-client-9.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2458536

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-27892c9184' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rpki-client
Product: Fedora 43
Version: 9.8
Release: 1.fc43
Summary: OpenBSD RPKI validator to support BGP Origin Validation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here