Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-31144

Опубликовано: 19 июл. 2022
Источник: redhat
CVSS3: 7

Описание

Redis is an in-memory database that persists on disk. A specially crafted XAUTOCLAIM command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

A heap-based buffer overflow flaw was found in Redis within the XAUTOCLAIM command implementation. This flaw allows an attacker to craft the XAUTOCLAIM command with malicious data on a stream key in a specific state that triggers a heap-based buffer overflow, possibly enabling remote code execution.

Отчет

The vulnerable code was introduced in Redis v7.0.0 and affects only Redis v7.0.0 and higher versions. Hence, Red Hat Enterprise Linux - 8, 9 with Redis v6.x.x are NOT-AFFECTED.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp-backend-containerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-api-rhel8Not affected
Red Hat Ansible Automation Platform 1.2ansible-towerNot affected
Red Hat Enterprise Linux 8redis:6/redisNot affected
Red Hat Enterprise Linux 9redisNot affected
Red Hat Fuse 7redisNot affected
Red Hat OpenStack Platform 13 (Queens)redisOut of support scope
Red Hat Quay 3quay/quay-rhel8Not affected
Red Hat Satellite 6satellite:el8/rubygem-gitlab-sidekiq-fetcherNot affected
Red Hat Satellite 6tfm-rubygem-gitlab-sidekiq-fetcherNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2140891redis: heap overflow via XAUTOCLAIM command

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
больше 3 лет назад

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

CVSS3: 7
nvd
больше 3 лет назад

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

CVSS3: 7
msrc
4 месяца назад

Potential heap overflow in Redis

CVSS3: 7
debian
больше 3 лет назад

Redis is an in-memory database that persists on disk. A specially craf ...

CVSS3: 7
fstec
больше 3 лет назад

Уязвимость системы управления базами данных (СУБД) Redis, связанная с переполнением буфера в куче, позволяющая нарушителю выполнить произвольный код

7 High

CVSS3