REDHAT-BUG-2298532: Integer Overflow
Published Jul 18, 2024
·Updated
In the vrrpipsetshandler handler (fglobalparser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.
Affected Software
1 affected component
Keepalived Keepalived<=2.3.1
Event History
Jul 18, 2024
Data Sourced
via Red Hat·01:20 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2298532?
The severity of REDHAT-BUG-2298532 is high due to the potential for integer overflow which can lead to unexpected behavior.
2
How do I fix REDHAT-BUG-2298532?
To fix REDHAT-BUG-2298532, upgrade to a version of Keepalived that is higher than 2.3.1.
3
What versions of Keepalived are affected by REDHAT-BUG-2298532?
Keepalived versions up to and including 2.3.1 are affected by REDHAT-BUG-2298532.
4
What conditions are necessary for REDHAT-BUG-2298532 to be exploited?
An empty ipset name must be configured by the user for REDHAT-BUG-2298532 to potentially be exploited.
5
Is there a workaround for REDHAT-BUG-2298532?
Currently, there is no official workaround for REDHAT-BUG-2298532; the recommended action is to apply the update.