{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:X7TUH4LWIPCIZICRFL43BLMKYI","short_pith_number":"pith:X7TUH4LW","schema_version":"1.0","canonical_sha256":"bfe743f17643c48ca0512af9b0ad8ac217c3335fe374b4839180bd840e9bee5b","source":{"kind":"arxiv","id":"2411.16518","version":1},"attestation_state":"computed","paper":{"title":"Poster: From Fort to Foe: The Threat of RCE in RPKI","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Haya Schulmann, Michael Waidner, Niklas Vogel, Oliver Jacobsen","submitted_at":"2024-11-25T16:01:02Z","abstract_excerpt":"In this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine running the software. We discuss the unique impact of this RCE on networks that use RPKI, illustrating that RCE vulnerabilities are especially severe in the context of RPKI. The design of RPKI makes RCE easy to exploit on a large scale, allows compromise of RPKI validation integrity, and enables a powerful vector for additional attacks on other critical components of the network, like the border routers.\n  We analyze the"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2411.16518","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-11-25T16:01:02Z","cross_cats_sorted":[],"title_canon_sha256":"7383ab34800f6ee7583a9f9093bc11c09110953032b119b785fcce8303aa265e","abstract_canon_sha256":"a5dd354c924fe221a299eae54ca802dfff7e8792e8bf0c0256eb65b3ed798613"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:40:10.642454Z","signature_b64":"LleijgmwQjgvTJ3uhfRBl+WnV+bFenw5QEbUctSYDY8oTE2vzFY3o/BECJK/bG6dvzasllpWlywiXHSlag6sBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bfe743f17643c48ca0512af9b0ad8ac217c3335fe374b4839180bd840e9bee5b","last_reissued_at":"2026-07-05T09:40:10.641988Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:40:10.641988Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Poster: From Fort to Foe: The Threat of RCE in RPKI","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Haya Schulmann, Michael Waidner, Niklas Vogel, Oliver Jacobsen","submitted_at":"2024-11-25T16:01:02Z","abstract_excerpt":"In this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine running the software. We discuss the unique impact of this RCE on networks that use RPKI, illustrating that RCE vulnerabilities are especially severe in the context of RPKI. The design of RPKI makes RCE easy to exploit on a large scale, allows compromise of RPKI validation integrity, and enables a powerful vector for additional attacks on other critical components of the network, like the border routers.\n  We analyze the"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2411.16518","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2411.16518/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2411.16518","created_at":"2026-07-05T09:40:10.642046+00:00"},{"alias_kind":"arxiv_version","alias_value":"2411.16518v1","created_at":"2026-07-05T09:40:10.642046+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2411.16518","created_at":"2026-07-05T09:40:10.642046+00:00"},{"alias_kind":"pith_short_12","alias_value":"X7TUH4LWIPCI","created_at":"2026-07-05T09:40:10.642046+00:00"},{"alias_kind":"pith_short_16","alias_value":"X7TUH4LWIPCIZICR","created_at":"2026-07-05T09:40:10.642046+00:00"},{"alias_kind":"pith_short_8","alias_value":"X7TUH4LW","created_at":"2026-07-05T09:40:10.642046+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/X7TUH4LWIPCIZICRFL43BLMKYI","json":"https://pith.science/pith/X7TUH4LWIPCIZICRFL43BLMKYI.json","graph_json":"https://pith.science/api/pith-number/X7TUH4LWIPCIZICRFL43BLMKYI/graph.json","events_json":"https://pith.science/api/pith-number/X7TUH4LWIPCIZICRFL43BLMKYI/events.json","paper":"https://pith.science/paper/X7TUH4LW"},"agent_actions":{"view_html":"https://pith.science/pith/X7TUH4LWIPCIZICRFL43BLMKYI","download_json":"https://pith.science/pith/X7TUH4LWIPCIZICRFL43BLMKYI.json","view_paper":"https://pith.science/paper/X7TUH4LW","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2411.16518&json=true","fetch_graph":"https://pith.science/api/pith-number/X7TUH4LWIPCIZICRFL43BLMKYI/graph.json","fetch_events":"https://pith.science/api/pith-number/X7TUH4LWIPCIZICRFL43BLMKYI/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/X7TUH4LWIPCIZICRFL43BLMKYI/action/timestamp_anchor","attest_storage":"https://pith.science/pith/X7TUH4LWIPCIZICRFL43BLMKYI/action/storage_attestation","attest_author":"https://pith.science/pith/X7TUH4LWIPCIZICRFL43BLMKYI/action/author_attestation","sign_citation":"https://pith.science/pith/X7TUH4LWIPCIZICRFL43BLMKYI/action/citation_signature","submit_replication":"https://pith.science/pith/X7TUH4LWIPCIZICRFL43BLMKYI/action/replication_record"}},"created_at":"2026-07-05T09:40:10.642046+00:00","updated_at":"2026-07-05T09:40:10.642046+00:00"}