CVE-2021-32762
Summary
| CVE | CVE-2021-32762 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-04 18:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a result of a vulnerability in the underlying hiredis library which does not perform an overflow check before calling the calloc() heap allocation function. This issue only impacts systems with heap allocators that do not perform their own overflow checks. Most modern systems do and are therefore not likely to be affected. Furthermore, by default redis-sentinel uses the jemalloc allocator which is also not vulnerable. The problem is fixed in Redis versions 6.2.6, 6.0.16 and 5.0.14. |
Risk And Classification
Problem Types: CWE-190 | CWE-680
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Application | Netapp | Management Services For Element Software | - | All | All | All |
| Application | Netapp | Management Services For Element Software And Netapp Hci | - | All | All | All |
| Application | Netapp | Management Services For Netapp Hci | - | All | All | All |
| Application | Oracle | Communications Operations Monitor | 4.3 | All | All | All |
| Application | Oracle | Communications Operations Monitor | 4.4 | All | All | All |
| Application | Oracle | Communications Operations Monitor | 5.0 | All | All | All |
| Application | Redis | Redis | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 33 Update: redis-6.0.16-1.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Redis: Multiple Vulnerabilities (GLSA 202209-17) — Gentoo security | GENTOO | security.gentoo.org | |
| Fix redis-cli / redis-sential overflow on some platforms (CVE-2021-32… · redis/redis@0215324 · GitHub | MISC | github.com | |
| [SECURITY] Fedora 33 Update: redis-6.0.16-1.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Debian -- Security Information -- DSA-5001-1 redis | DEBIAN | www.debian.org | |
| Oracle Critical Patch Update Advisory - April 2022 | MISC | www.oracle.com | |
| [SECURITY] Fedora 35 Update: redis-6.2.6-1.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| October 2021 Redis Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [SECURITY] Fedora 35 Update: redis-6.2.6-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Integer overflow that can lead to heap overflow in redis-cli, redis-sentinel on some platforms · Advisory · redis/redis · GitHub | CONFIRM | github.com | |
| [SECURITY] Fedora 34 Update: redis-6.2.6-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| FEDORA-2021-61c487f241 | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178879 Debian Security Update for redis (DSA 5001-1)
- 178883 Debian Security Update for redis (DLA 2810-1)
- 281978 Fedora Security Update for redis (FEDORA-2021-61c487f241)
- 281979 Fedora Security Update for redis (FEDORA-2021-8913c7900c)
- 356248 Amazon Linux Security Advisory for redis : ALASREDIS6-2023-007
- 376213 Redis Server Heap Overflow Vulnerability
- 500601 Alpine Linux Security Update for redis
- 501484 Alpine Linux Security Update for redis
- 501777 Alpine Linux Security Update for redis
- 504356 Alpine Linux Security Update for redis
- 690095 Free Berkeley Software Distribution (FreeBSD) Security Update for redis (9b4806c1-257f-11ec-9db5-0800270512f4)
- 710625 Gentoo Linux Redis Multiple Vulnerabilities (GLSA 202209-17)
- 751395 OpenSUSE Security Update for redis (openSUSE-SU-2021:3772-1)
- 900345 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (5970)
- 901651 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (6851-1)