Bug 29769 - keepalived new security issue CVE-2021-44225
Summary: keepalived new security issue CVE-2021-44225
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-12-14 22:33 CET by David Walser
Modified: 2021-12-19 13:27 CET (History)
3 users (show)

See Also:
Source RPM: keepalived-2.2.3-2.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-12-14 22:33:55 CET
Ubuntu has issued an advisory on December 13:
https://ubuntu.com/security/notices/USN-5188-1

The issue is fixed upstream but there's no new release with the fix yet.

Mageia 8 is also affected.
David Walser 2021-12-14 22:34:13 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patch available from upstream and Ubuntu

Comment 1 Nicolas Lécureuil 2021-12-14 23:26:34 CET
fixed in mga8/9

src:
    - keepalived-2.1.5-2.1.mga8

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
Assignee: bugsquad => qa-bugs
CC: (none) => mageia
Status comment: Patch available from upstream and Ubuntu => (none)

Comment 2 David Walser 2021-12-14 23:31:18 CET
Cauldron still needs to be updated to 2.2.4 as well.

Build failed in Mageia 8:
http://pkgsubmit.mageia.org/uploads/failure/8/core/updates_testing/20211214222526.neoclust.duvel.3199374/log/keepalived-2.1.5-2.1.mga8/build.x86_64.0.20211214222554.log

Assignee: qa-bugs => mageia

Comment 3 Nicolas Lécureuil 2021-12-14 23:56:25 CET
new version pushed in mga8:


src:
    - keepalived-2.2.3-3.mga8

Assignee: mageia => qa-bugs

Comment 4 David Walser 2021-12-15 00:00:48 CET
RPM and SRPM:
keepalived-2.2.3-3.mga8

2.2.4 pushed to Cauldron.
Comment 5 David Walser 2021-12-15 00:01:15 CET
If we're updating Mageia 8 from 2.1.5 to 2.2.x, we should update that to 2.2.4 as well.
Comment 7 Thomas Andrews 2021-12-15 19:32:58 CET
Referenced Bug 24063 for information, where I see that keepalived is described as a "big thing to drive," and was OKed based on a clean install and a check of the service status. 

There were no installation issues with this update.

[root@localhost ~]# systemctl status keepalived
● keepalived.service - LVS and VRRP High Availability Monitor
     Loaded: loaded (/usr/lib/systemd/system/keepalived.service; disabled; vendor preset: disabled)
     Active: inactive (dead)
       Docs: man:keepalived(8)
             man:keepalived.conf(5)
             man:genhash(1)
             https://keepalived.org

Dec 15 13:08:45 localhost Keepalived[14953]: pid 14955 exited with permanent error CONFIG. Terminating
Dec 15 13:08:45 localhost Keepalived[14953]: CPU usage (self/children) user: 0.005125/0.001018 system: 0.000000/0.000000
Dec 15 13:08:45 localhost Keepalived[14953]: Stopped Keepalived v2.2.4 (08/21,2021)
Dec 15 13:08:45 localhost Keepalived_healthcheckers[14954]: Shutting down service [192.168.201.100]:tcp:443 from VS [192.168.200.100]:tcp:443
Dec 15 13:08:45 localhost Keepalived_healthcheckers[14954]: Shutting down service [192.168.200.2]:tcp:1358 from VS [10.10.10.2]:tcp:1358
Dec 15 13:08:45 localhost Keepalived_healthcheckers[14954]: Shutting down service [192.168.200.3]:tcp:1358 from VS [10.10.10.2]:tcp:1358
Dec 15 13:08:45 localhost Keepalived_healthcheckers[14954]: Shutting down service [192.168.200.4]:tcp:1358 from VS [10.10.10.3]:tcp:1358
Dec 15 13:08:45 localhost Keepalived_healthcheckers[14954]: Shutting down service [192.168.200.5]:tcp:1358 from VS [10.10.10.3]:tcp:1358
Dec 15 13:08:45 localhost Keepalived_healthcheckers[14954]: Stopped - used 0.001702 user time, 0.000000 system time
Dec 15 13:08:45 localhost systemd[1]: keepalived.service: Succeeded.

It looks to me like the service tried to start, but was then shut down due to a CONFIG error. Since I didn't do anything configuration-wise, I believe it is working as expected, within what I can test.

Giving it an OK, and validating.

Whiteboard: (none) => MGA8-64-OK
Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2021-12-19 12:26:07 CET

Keywords: (none) => advisory

Comment 8 Mageia Robot 2021-12-19 13:27:45 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0567.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.