Integer overflow in Keepalived - CVE-2024-41184

 

Integer overflow in Keepalived - CVE-2024-41184

Published: August 28, 2024


Vulnerability identifier: #VU96580
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-41184
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to crash the application.

The vulnerability exists due to integer overflow within the vrrp_ipsets_handler handler in fglobal_parser.c. A local user can pass specially crafted arguments to the application, trigger an integer overflow and perform a denial of service (DoS) attack.


Affected software

Keepalived
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Availability Extension 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Server 15 SP2 Business Critical Linux
SUSE Linux Enterprise Server 15 SP3 Business Critical Linux
openSUSE Leap
keepalived-debuginfo
keepalived-debugsource
keepalived
keepalived (Red Hat package)
keepalived-doc
oath-toolkit (Red Hat package)
cephadm-ansible (Red Hat package)
ceph (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat Ceph Storage

How to mitigate CVE-2024-41184

Install updates from vendor's website.

keepalived-debuginfo - addressed in versions 2.0.19-150100.3.9.1, 2.2.2-150400.3.10.1, 2.2.2-150500.8.5.1, 2.2.8-150600.3.5.1
keepalived-debugsource - addressed in versions 2.0.19-150100.3.9.1, 2.2.2-150400.3.10.1, 2.2.2-150500.8.5.1, 2.2.8-150600.3.5.1
keepalived - addressed in versions 2.0.19-150100.3.9.1, 2.2.2-150400.3.10.1, 2.2.2-150500.8.5.1, 2.2.8-150600.3.5.1
keepalived (Red Hat package) - addressed in versions 2.1.5-10.el8_10, 2.2.8-4.el9_5
keepalived - addressed in versions 2.2.8-4, 2.3.2-1
keepalived-doc - update to 2.3.2-1
oath-toolkit (Red Hat package) - update to 2.6.12-1.el9cp
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
Red Hat OpenShift Container Platform - update to 4.14.46
Red Hat Ceph Storage - update to 8.1
ceph (Red Hat package) - update to 19.2.1-222.el9cp

External References

Related Security Bulletins