Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 35: 2021-0cda131052 Moderate: Keepalived D-Bus Access Control Fix

fedora
Calendar Grey December 22, 2021
Dist Fedora Esm H88
Upgrade to Fedora 35 for Keepalived, resolving a significant D-Bus policy concern tied to access management.
Fix dbus policy (#2027158, CVE-2021-44225)

Summary

Keepalived provides simple and robust facilities for load balancing

and high availability to Linux system and Linux based infrastructures.

The load balancing framework relies on well-known and widely used

Linux Virtual Server (IPVS) kernel module providing Layer4 load

balancing. Keepalived implements a set of checkers to dynamically and

adaptively maintain and manage load-balanced server pool according

their health. High availability is achieved by VRRP protocol. VRRP is

a fundamental brick for router failover. In addition, keepalived

implements a set of hooks to the VRRP finite state machine providing

low-level and high-speed protocol interactions. Keepalived frameworks

can be used independently or all together to provide resilient

infrastructures.

Fix dbus policy (#2027158, CVE-2021-44225)

* Tue Dec 14 2021 Ryan O'Hara - 2.2.4-2

- Fix dbus policy (#2027158, CVE-2021-44225)

[ 1 ] Bug #2027158 - CVE-2021-44225 keepalived: dbus access control bypass [fedora-34]

https://bugzilla.redhat.com/show_bug.cgi?id=2027158

su -c 'dnf upgrade --advisory FEDORA-2021-0cda131052' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Product: Fedora 35
Version: 2.2.4
Release: 2.fc35
Summary: High Availability monitor built upon LVS, VRRP and service pollers

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here