CVE-2021-32672
Summary
| CVE | CVE-2021-32672 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-04 18:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 33 Update: redis-6.0.16-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Redis: Multiple Vulnerabilities (GLSA 202209-17) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 33 Update: redis-6.0.16-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-5001-1 redis |
DEBIAN |
www.debian.org |
|
| Vulnerability in Lua Debugger · Advisory · redis/redis · GitHub |
CONFIRM |
github.com |
|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| [SECURITY] Fedora 35 Update: redis-6.2.6-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| October 2021 Redis Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] Fedora 35 Update: redis-6.2.6-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: redis-6.2.6-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Fix protocol parsing on 'ldbReplParseCommand' (CVE-2021-32672) · redis/redis@6ac3c0b · GitHub |
MISC |
github.com |
|
| FEDORA-2021-61c487f241 |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178879 Debian Security Update for redis (DSA 5001-1)
- 178883 Debian Security Update for redis (DLA 2810-1)
- 184048 Debian Security Update for redis (CVE-2021-32672)
- 281978 Fedora Security Update for redis (FEDORA-2021-61c487f241)
- 281979 Fedora Security Update for redis (FEDORA-2021-8913c7900c)
- 356248 Amazon Linux Security Advisory for redis : ALASREDIS6-2023-007
- 500601 Alpine Linux Security Update for redis
- 501484 Alpine Linux Security Update for redis
- 501777 Alpine Linux Security Update for redis
- 504356 Alpine Linux Security Update for redis
- 710625 Gentoo Linux Redis Multiple Vulnerabilities (GLSA 202209-17)
- 730240 Redis Server Arbitrary File Read Vulnerability
- 751395 OpenSUSE Security Update for redis (openSUSE-SU-2021:3772-1)
- 900489 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (5954)
- 901394 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (6847-1)