Описание
Denial-of-service due to malformed ACL selectors
Impact
An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service.
The problem exists in Redis 7.0.0 or newer.
Patches
The problem is fixed in Redis 7.2.6 and 7.4.1.
Credit
The problem was reported by Axel Mierczuk.
Пакеты
redis
>=7.2.0, <7.2.6
7.2.6
redis
>=7.4.0, <7.4.1
7.4.1
Связанные уязвимости
Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem exists in Redis 7 prior to versions 7.2.6 and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem exists in Redis 7 prior to versions 7.2.6 and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem exists in Redis 7 prior to versions 7.2.6 and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Denial-of-service due to malformed ACL selectors in Redis
Redis is an open source, in-memory database that persists on disk. An ...