VYPR
Unrated severityNVD Advisory· Published Sep 21, 2021· Updated Sep 16, 2024

Invalid RPKI data could disable Route Origin Validation on RTR clients.

CVE-2021-41531

Description

Routinator prior to 0.10.0 passes oversized max-length values in ROAs, causing RTR clients to reject RPKI data and disabling Route Origin Validation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Routinator prior to 0.10.0 passes oversized max-length values in ROAs, causing RTR clients to reject RPKI data and disabling Route Origin Validation.

Vulnerability

In Routinator versions prior to 0.10.0, the software does not validate the max-length parameter in a ROA generated by an RPKI CA. According to [1], Routinator will simply pass through any max-length value provided in the ROA. However, a max-length value must never be larger than the maximum prefix length of the address family (32 for IPv4, 128 for IPv6). If a CA uses an excessively large value, Routinator produces an invalid RTR payload. All versions up to and including 0.9.0 are affected [1].

Exploitation

An attacker who controls or compromises an RPKI CA can craft a ROA with an oversized max-length parameter. No authentication or special network position is required beyond the ability to publish such a ROA. When Routinator processes the malformed ROA, it generates an invalid RTR payload without error checking [1]. The invalid payload is then sent to RTR clients (e.g., routers). The attack does not require user interaction; it occurs automatically during the standard RTR update cycle.

Impact

RTR clients that receive the invalid payload will reject the entire RPKI data set [1]. This effectively disables Route Origin Validation (ROV) on those clients, meaning they will no longer validate BGP route origins based on RPKI. No confidentiality or integrity impact is described; the primary impact is availability of the ROV security function.

Mitigation

Upgrade to Routinator 0.10.0 or later, which includes validation of the max-length parameter [1]. The fixed version was released on the same date as the advisory (2021-09-21). No workaround is documented for unpatched versions; administrators should apply the update as soon as possible.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.