Home / mailings [USN-7813-1] FORT Validator vulnerabilities
Posted on 08 October 2025
Ubuntu Security==========================================================================Ubuntu Security Notice USN-7813-1
October 08, 2025
fort-validator vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in FORT Validator.
Software Description:
- fort-validator: RPKI validator and RTR server
Details:
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing certain RPKI repository data.
A remote attacker could possibly use this issue to cause FORT Validator to
crash, resulting in a denial of service. (CVE-2024-45234, CVE-2024-45235,
CVE-2024-45236, CVE-2024-45238, CVE-2024-45239)
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing resource certificates. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2024-45237)
Koen van Hove discovered that FORT Validator did not limit the duration of
data transfers when fetching RPKI repository data. A remote attacker could
possibly use this issue to cause FORT Validator to consume excessive
resources, resulting in a denial of service. (CVE-2024-48943)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
fort-validator 1.6.1-1ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 22.04 LTS
fort-validator 1.5.3-1ubuntu0.1
Ubuntu 20.04 LTS
fort-validator 1.2.0-1ubuntu0.1~esm1
Available with Ubuntu Pro
After a standard system update you need to restart FORT Validator to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7813-1
CVE-2024-45234, CVE-2024-45235, CVE-2024-45236, CVE-2024-45237,
CVE-2024-45238, CVE-2024-45239, CVE-2024-48943
Package Information:
https://launchpad.net/ubuntu/+source/fort-validator/1.5.3-1ubuntu0.1
--===============5596463463557189901==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature