CVE-2018-19115: Debian Linux
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.
Affected products
- Debian Debian Linux: version 8.0 only
- Keepalived Keepalived: before 2.0.7 (fixed in 2.0.7)
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only
- Red Hat Enterprise Linux Server Tus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-11-08. Last modified 2026-06-17.