Описание
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
A flaw was found in Redis. When processing a certain sequence of payloads, Redis may incorrectly handle the resizing of memory buffers, leading to a heap-based buffer overflow, potentially resulting in a denial of service or remote code execution.
Отчет
The redis package, as shipped with Red Hat Enterprise Linux 8, 9, and RHSCL is not affected by this vulnerability because the vulnerable code was introduced in a newer version of redis. However, the redis:7 module as shipped with Red Hat Enterprise Linux 9.3 is affected.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat 3scale API Management Platform 2 | 3scale-amp-backend-container | Not affected | ||
Red Hat 3scale API Management Platform 2 | 3scale-amp-system-container | Not affected | ||
Red Hat Ansible Automation Platform 1.2 | ansible-tower | Out of support scope | ||
Red Hat Enterprise Linux 8 | redis:6/redis | Not affected | ||
Red Hat Enterprise Linux 9 | redis | Not affected | ||
Red Hat Fuse 7 | redis | Not affected | ||
Red Hat Quay 3 | quay/quay-rhel8 | Affected | ||
Red Hat Software Collections | rh-redis6-redis | Not affected | ||
Red Hat Enterprise Linux 9 | redis | Fixed | RHEA-2024:1143 | 05.03.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Redis is an in-memory database that persists on disk. Redis incorrectl ...
Уязвимость системы управления базами данных (СУБД) Redis, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код
EPSS
8.1 High
CVSS3