Integer Underflow Vulnerability in Fort Product Line
CVE-2024-56375
7.5HIGH
What is CVE-2024-56375?
A critical flaw was identified in Fort versions 1.6.3 and 1.6.4, where an integer underflow occurs when a malicious RPKI repository serves a Manifest RPKI object containing an empty fileList. This design oversight leads to an out-of-bounds access as the Fort validator attempts to dereference an empty array, causing its shuffle operation to enter an infinite loop. As a result, the product becomes unresponsive, as it continuously tries to process a non-existent array, ultimately leading to a guaranteed system crash.
Affected Version(s)
fort-validator 1.6.3 < 1.6.5
