Описание
Redis is an in-memory database that persists on disk. A specially crafted XAUTOCLAIM command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.
A heap-based buffer overflow flaw was found in Redis within the XAUTOCLAIM command implementation. This flaw allows an attacker to craft the XAUTOCLAIM command with malicious data on a stream key in a specific state that triggers a heap-based buffer overflow, possibly enabling remote code execution.
Отчет
The vulnerable code was introduced in Redis v7.0.0 and affects only Redis v7.0.0 and higher versions. Hence, Red Hat Enterprise Linux - 8, 9 with Redis v6.x.x are NOT-AFFECTED.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat 3scale API Management Platform 2 | 3scale-amp-backend-container | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-api-rhel8 | Not affected | ||
| Red Hat Ansible Automation Platform 1.2 | ansible-tower | Not affected | ||
| Red Hat Enterprise Linux 8 | redis:6/redis | Not affected | ||
| Red Hat Enterprise Linux 9 | redis | Not affected | ||
| Red Hat Fuse 7 | redis | Not affected | ||
| Red Hat OpenStack Platform 13 (Queens) | redis | Out of support scope | ||
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | ||
| Red Hat Satellite 6 | satellite:el8/rubygem-gitlab-sidekiq-fetcher | Not affected | ||
| Red Hat Satellite 6 | tfm-rubygem-gitlab-sidekiq-fetcher | Not affected |
Показывать по
Дополнительная информация
Статус:
7 High
CVSS3
Связанные уязвимости
Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.
Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.
Redis is an in-memory database that persists on disk. A specially craf ...
Уязвимость системы управления базами данных (СУБД) Redis, связанная с переполнением буфера в куче, позволяющая нарушителю выполнить произвольный код
7 High
CVSS3