Name
keepalived
Version
2.2.2
Type
library
Description
High Availability monitor built upon LVS, VRRP and service pollers
Licenses
GPL-2.0-only
PURL
-
CPE
cpe:2.3:*:keepalived:keepalived:2.2.2:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
lib: don't return subtracted addresses for rb_find() compare
Quentin Armitage <quentin@armitage.org.uk>
CVE-2024-41184
2
layer4: Change order of include files
Khem Raj <raj.khem@gmail.com>
3
vrrp: Handle empty ipset names with vrrp_ipsets keyword
Quentin Armitage <quentin@armitage.org.uk>
CVE-2024-41184
4
vrrp and ipvs: handle empty nftables chain names
Quentin Armitage <quentin@armitage.org.uk>
CVE-2024-41184
5
vrrp: handle empty iptables chain names - vrrp_iptables
Quentin Armitage <quentin@armitage.org.uk>
CVE-2024-41184
6
dbus: fix policy to not be overly broad
Vincent Bernat <vincent@bernat.ch>
CVE-2021-44225
Vulnerabilities#
Name
Analysis
Description
Patched
In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.
Patched
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property