* bsc#1228123 Cross-References: * CVE-2024-41184 . # Security update for keepalived Announcement ID: SUSE-SU-2025:20039-1 Release Date: 2025-02-03T08:53:39Z Rating: moderate References: * bsc#1228123 Cross-References: * CVE-2024-41184 CVSS scores: * CVE-2024-41184 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for keepalived fixes the following issues: * CVE-2024-41184: Fixed integer overflow in vrrp_ipsets_handler (bsc#1228123) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-72=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * keepalived-debugsource-2.2.8-2.1 * keepalived-2.2.8-2.1 * keepalived-debuginfo-2.2.8-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-41184.html * https://bugzilla.suse.com/show_bug.cgi?id=1228123 . Patch released for keepalived integer overflow vulnerability in SUSE Linux Micro. Make sure your system is updated to maintain security integrity.. SUSE Linux Micro, keepalived update, integer overflow fix, security advisory, SUSE patch. . LinuxSecurity.com Team
* bsc#1228123 Cross-References: * CVE-2024-41184 . # Security update for keepalived Announcement ID: SUSE-SU-2025:20039-1 Release Date: 2025-02-03T08:53:39Z Rating: moderate References: * bsc#1228123 Cross-References: * CVE-2024-41184 CVSS scores: * CVE-2024-41184 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for keepalived fixes the following issues: * CVE-2024-41184: Fixed integer overflow in vrrp_ipsets_handler (bsc#1228123) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-72=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * keepalived-debuginfo-2.2.8-2.1 * keepalived-2.2.8-2.1 * keepalived-debugsource-2.2.8-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-41184.html * https://bugzilla.suse.com/show_bug.cgi?id=1228123 . A new SUSE Linux Micro update addresses a critical integer overflow flaw in keepalived, rated as "High" severity to bolster system security against exploits. SUSE Linux Micro, keepalived update, integer overflow fix, security advisory. . LinuxSecurity.com Team
Moderate: keepalived security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:0743", "synopsis": "Moderate: keepalived security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for keepalived.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The keepalived utility provides simple and robust facilities for load balancing and high availability. The load balancing framework relies on the well-known and widely used IP Virtual Server (IPVS) kernel module providing layer-4 (transport layer) load balancing. Keepalived implements a set of checkers to dynamically and adaptively maintain and manage a load balanced server pool according to the health of the servers. Keepalived also implements the Virtual Router Redundancy Protocol (VRRPv2) to achieve high availability with director failover.\n\nSecurity Fix(es):\n\n* keepalived: Integer overflow vulnerability in vrrp_ipsets_handler (CVE-2024-41184)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2298532", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2298532", "description": ""}], "cves": [{"name": "CVE-2024-41184", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-41184", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2025-02-13T20:34:26.141542Z", "rpms": {"Rocky Linux 8": {"nvras": ["keepalived-0:2.1.5-10.el8_10.aarch64.rpm", "keepalived-0:2.1.5-10.el8_10.src.rpm", "keepalived-0:2.1.5-10.el8_10.x86_64.rpm", "keepalived-debuginfo-0:2.1.5-10.el8_10.aarch64.rpm", "keepalived-debuginfo-0:2.1.5-10.el8_10.x86_64.rpm","keepalived-debugsource-0:2.1.5-10.el8_10.aarch64.rpm", "keepalived-debugsource-0:2.1.5-10.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. AlmaLinux unveils a significant security patch for haproxy, fixing a buffer overflow vulnerability. Upgrade today!. keepalived Security Update, Rocky Linux Advisory, Load Balancing Security. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0917 http://linux.oracle.com/errata/ELSA-2025-0917.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: keepalived-2.2.8-4.el9_5.x86_64.rpm aarch64: keepalived-2.2.8-4.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//keepalived-2.2.8-4.el9_5.src.rpm Related CVEs: CVE-2024-41184 Description of changes: [2.2.8-3] - Validate vrrp ipset names for CVE-2024-41184 Resolves: RHEL-49557 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0743 http://linux.oracle.com/errata/ELSA-2025-0743.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: keepalived-2.1.5-10.el8_10.x86_64.rpm aarch64: keepalived-2.1.5-10.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//keepalived-2.1.5-10.el8_10.src.rpm Related CVEs: CVE-2024-41184 Description of changes: [2.1.5-10] - CVE-2024-41184 Resolves: RHEL-49561 _______________________________________________ El-errata mailing list
* bsc#1228123 Cross-References: * CVE-2024-41184 . # Security update for keepalived Announcement ID: SUSE-SU-2024:3633-1 Release Date: 2024-10-15T09:20:42Z Rating: moderate References: * bsc#1228123 Cross-References: * CVE-2024-41184 CVSS scores: * CVE-2024-41184 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for keepalived fixes the following issues: * CVE-2024-41184: Fixed integer overflow in vrrp_ipsets_handler (bsc#1228123) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-3633=1 openSUSE-SLE-15.6-2024-3633=1 * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2024-3633=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * keepalived-debugsource-2.2.8-150600.3.5.1 * keepalived-2.2.8-150600.3.5.1 * keepalived-debuginfo-2.2.8-150600.3.5.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * keepalived-debugsource-2.2.8-150600.3.5.1 * keepalived-2.2.8-150600.3.5.1 * keepalived-debuginfo-2.2.8-150600.3.5.1 ## References: * https://www.suse.com/security/cve/CVE-2024-41184.html * https://bugzilla.suse.com/show_bug.cgi?id=1228123 . SUSE has announced updates for keepalived that tackle several moderate vulnerabilities, including a resolution for an integer overflow in the vrrp_ipsets_handler.. SUSE updates, keepalived security, software patch, integer overflow fix. . LinuxSecurity.com Team
* bsc#1228123 Cross-References: * CVE-2024-41184 . # Security update for keepalived Announcement ID: SUSE-SU-2024:3634-1 Release Date: 2024-10-15T09:21:36Z Rating: moderate References: * bsc#1228123 Cross-References: * CVE-2024-41184 CVSS scores: * CVE-2024-41184 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.5 * openSUSE Leap Micro 5.5 * SUSE Linux Enterprise High Availability Extension 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for keepalived fixes the following issues: * CVE-2024-41184: Fixed integer overflow in vrrp_ipsets_handler (bsc#1228123) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2024-3634=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-3634=1 openSUSE-SLE-15.5-2024-3634=1 * openSUSE Leap Micro 5.5 zypper in -t patch openSUSE-Leap-Micro-5.5-2024-3634=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-3634=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP5 (aarch64 ppc64le s390x x86_64) * keepalived-2.2.2-150500.8.5.1 * keepalived-debuginfo-2.2.2-150500.8.5.1 * keepalived-debugsource-2.2.2-150500.8.5.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * keepalived-2.2.2-150500.8.5.1 * keepalived-debuginfo-2.2.2-150500.8.5.1 * keepalived-debugsource-2.2.2-150500.8.5.1 * openSUSE Leap Micro 5.5 (aarch64 s390x x86_64) * keepalived-2.2.2-150500.8.5.1 *keepalived-debuginfo-2.2.2-150500.8.5.1 * keepalived-debugsource-2.2.2-150500.8.5.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * keepalived-2.2.2-150500.8.5.1 * keepalived-debuginfo-2.2.2-150500.8.5.1 * keepalived-debugsource-2.2.2-150500.8.5.1 ## References: * https://www.suse.com/security/cve/CVE-2024-41184.html * https://bugzilla.suse.com/show_bug.cgi?id=1228123 . The security advisory SUSE-SU-2024:3645-1 highlights a noteworthy buffer overflow vulnerability in Keepalived. It is advised to implement the update promptly.. keepalived security advisory, SUSE updates, high availability patch, integer overflow fix. . LinuxSecurity.com Team
* bsc#1228123 Cross-References: * CVE-2024-41184 . # Security update for keepalived Announcement ID: SUSE-SU-2024:3031-1 Rating: moderate References: * bsc#1228123 Cross-References: * CVE-2024-41184 CVSS scores: * CVE-2024-41184 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for keepalived fixes the following issues: * CVE-2024-41184: Fixed integer overflow in vrrp_ipsets_handler (bsc#1228123) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-3031=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-3031=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-3031=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-3031=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-3031=1 * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2024-3031=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * keepalived-2.2.2-150400.3.10.1 * keepalived-debugsource-2.2.2-150400.3.10.1 *keepalived-debuginfo-2.2.2-150400.3.10.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * keepalived-2.2.2-150400.3.10.1 * keepalived-debugsource-2.2.2-150400.3.10.1 * keepalived-debuginfo-2.2.2-150400.3.10.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * keepalived-2.2.2-150400.3.10.1 * keepalived-debugsource-2.2.2-150400.3.10.1 * keepalived-debuginfo-2.2.2-150400.3.10.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * keepalived-2.2.2-150400.3.10.1 * keepalived-debugsource-2.2.2-150400.3.10.1 * keepalived-debuginfo-2.2.2-150400.3.10.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * keepalived-2.2.2-150400.3.10.1 * keepalived-debugsource-2.2.2-150400.3.10.1 * keepalived-debuginfo-2.2.2-150400.3.10.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * keepalived-2.2.2-150400.3.10.1 * keepalived-debugsource-2.2.2-150400.3.10.1 * keepalived-debuginfo-2.2.2-150400.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2024-41184.html * https://bugzilla.suse.com/show_bug.cgi?id=1228123 . Recent updates on the moderate severity keepalived security advisory for SUSE systems address integer overflow vulnerabilities, emphasizing essential patches to enhance system integrity.. Keepalived Security Update,SUSE Patch Instructions,Keepalived Integer Overflow. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.