SB2021112614 - Security restrictions bypass in Keepalived
Published: November 26, 2021 Updated: August 29, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2021-44225)
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to the D-Bus policy does not sufficiently restrict the message destination. A local user can inspect and manipulate any property in the message and bypass implemented security restrictions.
Remediation
Install update from vendor's website.
References
- https://github.com/acassen/keepalived/commit/7977fec0be89ae6fe87405b3f8da2f0b5e415e3d
- https://github.com/acassen/keepalived/pull/2063
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5226RYNMNB7FL4MSJDIBBGPUWH6LMRYV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6O2R6EXURJQFPFPYFWRCZLUYVWQCLSZM/