CVE-2022-24736
Summary
| CVE | CVE-2022-24736 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-27 20:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Redis: Multiple Vulnerabilities (GLSA 202209-17) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Lua readonly tables (CVE-2022-24736, CVE-2022-24735) by oranagra · Pull Request #10651 · redis/redis · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: redis-6.2.7-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: redis-6.2.7-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Release 6.2.7 · redis/redis · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 36 Update: redis-6.2.7-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| June 2022 Redis Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] Fedora 36 Update: redis-6.2.7-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Release 7.0.0 · redis/redis · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: redis-6.2.7-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| A Malformed Lua script can crash Redis · Advisory · redis/redis · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 34 Update: redis-6.2.7-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160251 Oracle Enterprise Linux Security Update for redis:6 (ELSA-2022-7541)
- 160274 Oracle Enterprise Linux Security Update for redis (ELSA-2022-8096)
- 183270 Debian Security Update for redis (CVE-2022-24736)
- 240842 Red Hat Update for redis:6 security (RHSA-2022:7541)
- 240892 Red Hat Update for redis (RHSA-2022:8096)
- 282657 Fedora Security Update for redis (FEDORA-2022-a0a4c7eb31)
- 282658 Fedora Security Update for redis (FEDORA-2022-44373f6778)
- 282724 Fedora Security Update for redis (FEDORA-2022-6ed1ce2838)
- 354282 Amazon Linux Security Advisory for redis6 : ALAS2022-2022-115
- 354379 Amazon Linux Security Advisory for redis6 : ALAS2022-2022-199
- 355285 Amazon Linux Security Advisory for redis6 : ALAS2023-2023-064
- 356197 Amazon Linux Security Advisory for redis : ALASREDIS6-2023-003
- 501778 Alpine Linux Security Update for redis
- 504357 Alpine Linux Security Update for redis
- 690857 Free Berkeley Software Distribution (FreeBSD) Security Update for redis (cc42db1c-c65f-11ec-ad96-0800270512f4)
- 710625 Gentoo Linux Redis Multiple Vulnerabilities (GLSA 202209-17)
- 753389 SUSE Enterprise Linux Security Update for redis (SUSE-SU-2022:1929-1)
- 753479 SUSE Enterprise Linux Security Update for redis (SUSE-SU-2022:1842-1)
- 901279 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (9599)
- 901293 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (9628)
- 902313 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (9599-1)
- 902492 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (9628-1)
- 940762 AlmaLinux Security Update for redis:6 (ALSA-2022:7541)
- 940817 AlmaLinux Security Update for redis (ALSA-2022:8096)
- 960477 Rocky Linux Security Update for redis (RLSA-2022:8096)