Bugzilla – Bug 1228123
VUL-0: CVE-2024-41184: keepalived: integer overflow in vrrp_ipsets_handler
Last modified: 2024-07-19 19:22:54 UTC
In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41184 https://www.cve.org/CVERecord?id=CVE-2024-41184 https://github.com/acassen/keepalived/issues/2447#issuecomment-2231329734 https://bugzilla.redhat.com/show_bug.cgi?id=2298532