CVE-2022-24736
Published on: Not Yet Published
Last Modified on: 10/07/2022 03:26:00 PM UTC
Certain versions of Fedora from Fedoraproject contain the following vulnerability:
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.
- CVE-2022-24736 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
redis - redis version < 6.2.7
- Affected Vendor/Software:
redis - redis version < 7.0.0
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 2.1 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Redis: Multiple Vulnerabilities (GLSA 202209-17) — Gentoo security | security.gentoo.org text/html |
![]() |
Lua readonly tables (CVE-2022-24736, CVE-2022-24735) by oranagra · Pull Request #10651 · redis/redis · GitHub | github.com text/html |
![]() |
[SECURITY] Fedora 34 Update: redis-6.2.7-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Release 6.2.7 · redis/redis · GitHub | github.com text/html |
![]() |
[SECURITY] Fedora 36 Update: redis-6.2.7-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
June 2022 Redis Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Release 7.0.0 · redis/redis · GitHub | github.com text/html |
![]() |
[SECURITY] Fedora 35 Update: redis-6.2.7-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
A Malformed Lua script can crash Redis · Advisory · redis/redis · GitHub | github.com text/html |
![]() |
Oracle Critical Patch Update Advisory - July 2022 | www.oracle.com text/html |
![]() |
Related QID Numbers
- 160251 Oracle Enterprise Linux Security Update for redis:6 (ELSA-2022-7541)
- 160274 Oracle Enterprise Linux Security Update for redis (ELSA-2022-8096)
- 240842 Red Hat Update for redis:6 security (RHSA-2022:7541)
- 240892 Red Hat Update for redis (RHSA-2022:8096)
- 282657 Fedora Security Update for redis (FEDORA-2022-a0a4c7eb31)
- 282658 Fedora Security Update for redis (FEDORA-2022-44373f6778)
- 282724 Fedora Security Update for redis (FEDORA-2022-6ed1ce2838)
- 354282 Amazon Linux Security Advisory for redis6 : ALAS2022-2022-115
- 354379 Amazon Linux Security Advisory for redis6 : ALAS2022-2022-199
- 501778 Alpine Linux Security Update for redis
- 690857 Free Berkeley Software Distribution (FreeBSD) Security Update for redis (cc42db1c-c65f-11ec-ad96-0800270512f4)
- 710625 Gentoo Linux Redis Multiple Vulnerabilities (GLSA 202209-17)
- 753389 SUSE Enterprise Linux Security Update for redis (SUSE-SU-2022:1929-1)
- 753479 SUSE Enterprise Linux Security Update for redis (SUSE-SU-2022:1842-1)
- 901279 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (9599)
- 901293 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (9628)
- 902313 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (9599-1)
- 902492 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (9628-1)
- 940762 AlmaLinux Security Update for redis:6 (ALSA-2022:7541)
- 940817 AlmaLinux Security Update for redis (ALSA-2022:8096)
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Fedoraproject | Fedora | 34 | All | All | All |
Operating System | Fedoraproject | Fedora | 35 | All | All | All |
Operating System | Fedoraproject | Fedora | 36 | All | All | All |
Application | Netapp | Management Services For Element Software | - | All | All | All |
Application | Netapp | Management Services For Netapp Hci | - | All | All | All |
Application | Oracle | Communications Operations Monitor | 4.3 | All | All | All |
Application | Oracle | Communications Operations Monitor | 4.4 | All | All | All |
Application | Oracle | Communications Operations Monitor | 5.0 | All | All | All |
Application | Redis | Redis | All | All | All | All |
Application | Redis | Redis | 7.0 | rc1 | All | All |
Application | Redis | Redis | 7.0 | rc2 | All | All |
Application | Redis | Redis | 7.0 | rc3 | All | All |
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_operations_monitor:4.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_operations_monitor:4.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_operations_monitor:5.0:*:*:*:*:*:*:*:
- cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*:
- cpe:2.3:a:redis:redis:7.0:rc1:*:*:*:*:*:*:
- cpe:2.3:a:redis:redis:7.0:rc2:*:*:*:*:*:*:
- cpe:2.3:a:redis:redis:7.0:rc3:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
? Redis (@Redisinc) v6.2.7 and v7.0.0 released to address CVE-2022-24735 and CVE-2022-24736: "By exploiting weakne… twitter.com/i/web/status/1… | 2022-04-27 15:33:25 |
![]() |
[RELEASE] Redis 6.2.7 is out! Upgrade urgency: SECURITY. * CVE-2022-24736 * CVE-2022-24735 Mailing list discussi… twitter.com/i/web/status/1… | 2022-04-27 17:03:52 |
![]() |
CVE-2022-24736 : Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attack… twitter.com/i/web/status/1… | 2022-04-27 19:59:48 |
![]() |
CVE-2022-24736 | 2022-04-27 20:57:08 |
![]() |
Seems Like OPNsense 22.1.6 Really Needs an Update Soon... | 2022-05-05 18:58:28 |
![]() |
DSM Version: 7.1.1-42951 (Release Candidate) | 2022-08-10 06:07:14 |
![]() |
Has anyone seen the release notes for the latest DSM 7.1.1 Release Candidate. Fixes a scary amount of CVEs. | 2022-08-16 14:26:29 |
![]() |
DSM 7.1.1-42962 released! | 2022-09-05 11:39:36 |