Описание
setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| redict | fixed | 7.3.5+ds-1 | package | |
| redis | unfixed | package | ||
| valkey | fixed | 8.1.1+dfsg1-2 | package |
Примечания
https://github.com/redis/redis/issues/14199
https://github.com/valkey-io/valkey/pull/2101
Fixed by: https://github.com/valkey-io/valkey/commit/374718b2a365ca69f715d542709b7d71540b1387
Redis upstream considers this issue only defensive programming / hardening, cf.
https://github.com/redis/redis/issues/14199#issuecomment-3076467634
EPSS
Связанные уязвимости
setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.
setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.
setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.
setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow
setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.
EPSS