Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Fedora 44 routinator Important RPKI Application Error Fix 2026-ec9f1ca21a

fedora
Calendar Grey July 21, 2026
Scroller Fedora
Routinator in Fedora 44 updated to fix critical flaws, including path traversal and application errors. Upgrade recommended.
Update routinator to the latest, pulling in updated dependencies (rpki and syslog), and switch fern to using syslog 7 instead of 6 for this update, and loosen the syslog version bo...

Summary

An RPKI relying party software.

Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and syslog), and switch fern to using syslog 7 instead of 6 for this update, and loosen the syslog version bound for ifcfg-devname. v0.15.2 This release fixes a number of vulnerabilities and security issues identified by a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency. We advise all users to upgrade at their earliest convenience. Security fixes Changed how transient errors when accepting incoming HTTP and RTR connections are handled: instead of exiting, a warning is printed and the error is ignored. ([#1099]) This issue was assigned CVE-2026-49232. Extended the check for illegal path components in rsync URIs to also include the authority and module parts. (via rpki-rs#370) This fixes a path traversal vulnerability that has been assigned CVE-2026-49233. Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373) This fixes a vulnerability that has been assigned CVE-2...

Change Log

* Thu Jul 2 2026 Michel Lind - 0.15.2-1 - Update to version 0.15.2; Resolves RHBZ#2400457

References


[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2300127 [ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2396345 [ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2400457 [ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497975

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ec9f1ca21a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: rust-routinator
Product: Fedora 44
Version: 0.15.2
Release: 1.fc44
Summary: RPKI relying party software

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.