CVE-2021-44225
published 2021-11-26CVE-2021-44225: In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
1.16%
63.5th percentile
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keepalived | < keepalived 1:2.2.4-0.2 (bookworm) | keepalived 1:2.2.4-0.2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| keepalived | keepalived | <= 2.2.4 | — |
| keepalived | keepalived | >= 0 < 1:2.1.5-0.2+deb11u1 | 1:2.1.5-0.2+deb11u1 |
| keepalived | keepalived | >= 0 < 1:2.2.4-0.2 | 1:2.2.4-0.2 |
| keepalived | keepalived | >= 0 < 1:2.2.4-0.2 | 1:2.2.4-0.2 |
| keepalived | keepalived | >= 0 < 1:2.2.4-0.2 | 1:2.2.4-0.2 |
| msrc | cbl2_keepalived_2.2.7-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_keepalived_2.0.10-7_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_msrc5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Keepalived vulnerability
vendor_ubuntu·2021-12-13
CVE-2021-44225 Keepalived vulnerability
Title: Keepalived vulnerability
Summary: Keepalived could be made to access-control bypass if it received a specially
crafted message.
It was discovered that Keepalived incorrectly handled certain messages.
An attacker could possibly use this issue to access-control bypass.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
keepalived: dbus access control bypass
vendor_redhat·2021-11-26·CVSS 5.4
CVE-2021-44225 [MEDIUM] CWE-287 keepalived: dbus access control bypass
keepalived: dbus access control bypass
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
A flaw was found in keepalived, where an improper authentication vulnerability allows an unprivileged user to change properties that could lead to an access-control bypass.
Package: keepalived (Red Hat Enterprise Linux 6) - Out of support scope
Package: keepalived (Red Hat Enterprise Linux 7) - Out of support scope
Package: keepalived (Red Hat Enterprise Linux 9) - Not affected
Microsoft
In Keepalived through 2.2.4 the D-Bus policy does not sufficiently restrict the message destination allowing any user to inspect and manipulate any property. This leads to access-control bypass in som
vendor_msrc·2021-11-09·CVSS 5.4
CVE-2021-44225 [MEDIUM] In Keepalived through 2.2.4 the D-Bus policy does not sufficiently restrict the message destination allowing any user to inspect and manipulate any property. This leads to access-control bypass in som
In Keepalived through 2.2.4 the D-Bus policy does not sufficiently restrict the message destination allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog pos
Debian
CVE-2021-44225: keepalived - In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the...
vendor_debian·2021·CVSS 5.4
CVE-2021-44225 [MEDIUM] CVE-2021-44225: keepalived - In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the...
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
Scope: local
bookworm: resolved (fixed in 1:2.2.4-0.2)
bullseye: resolved (fixed in 1:2.1.5-0.2+deb11u1)
forky: resolved (fixed in 1:2.2.4-0.2)
sid: resolved (fixed in 1:2.2.4-0.2)
trixie: resolved (fixed in 1:2.2.4-0.2)
GHSA
GHSA-jpw2-cwxg-4qv8: In Keepalived through 2
ghsa_unreviewed·2021-11-27
CVE-2021-44225 [MEDIUM] CWE-668 GHSA-jpw2-cwxg-4qv8: In Keepalived through 2
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
OSV
CVE-2021-44225: In Keepalived through 2
osv·2021-11-26·CVSS 5.4
CVE-2021-44225 [MEDIUM] CVE-2021-44225: In Keepalived through 2
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/acassen/keepalived/commit/7977fec0be89ae6fe87405b3f8da2f0b5e415e3dhttps://github.com/acassen/keepalived/pull/2063https://lists.debian.org/debian-lts-announce/2023/04/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5226RYNMNB7FL4MSJDIBBGPUWH6LMRYV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6O2R6EXURJQFPFPYFWRCZLUYVWQCLSZM/https://github.com/acassen/keepalived/commit/7977fec0be89ae6fe87405b3f8da2f0b5e415e3dhttps://github.com/acassen/keepalived/pull/2063https://lists.debian.org/debian-lts-announce/2023/04/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5226RYNMNB7FL4MSJDIBBGPUWH6LMRYV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6O2R6EXURJQFPFPYFWRCZLUYVWQCLSZM/
2021-11-26
Published