Medium severity4.7NVD Advisory· Published Nov 8, 2018· Updated Jun 17, 2026
CVE-2018-19044
CVE-2018-19044
Description
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.data or /tmp/keepalived.stats to /etc/passwd.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:keepalived:keepalived:2.0.8:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:keepalived:keepalived:2.0.8:*:*:*:*:*:*:*
- (no CPE)range: <2.0.8
- osv-coords2 versionspkg:rpm/suse/keepalived&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1pkg:rpm/opensuse/keepalived&distro=openSUSE%20Tumbleweed
< 2.0.19-3.3.1+ 1 more
- (no CPE)range: < 2.0.19-3.3.1
- (no CPE)range: < 2.2.2-4.2
Patches
Vulnerability mechanics
References
5- github.com/acassen/keepalived/commit/04f2d32871bb3b11d7dc024039952f2fe2750306nvdPatchThird Party Advisory
- github.com/acassen/keepalived/issues/1048nvdExploitPatchThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/201903-01nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2285nvd
News mentions
0No linked articles in our index yet.