CVE-2022-24834
Summary
| CVE | CVE-2022-24834 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-13 15:15:00 UTC |
| Updated | 2023-08-14 19:15:00 UTC |
| Description | Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20. |
Risk And Classification
Problem Types: CWE-122 | CWE-680
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Operating System | Fedoraproject | Fedora | 38 | All | All | All |
| Application | Redis | Redis | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Heap overflow issue with the Lua cjson and cmsgpack libraries used by Redis · Advisory · redis/redis · GitHub | MISC | github.com | |
| CVE-2022-24834 Redis Vulnerability in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| [SECURITY] Fedora 38 Update: redis-7.0.12-1.fc38 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: redis-7.0.12-1.fc37 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199978 Ubuntu Security Notification for Redis Vulnerabilities (USN-6531-1)
- 284322 Fedora Security Update for redis (FEDORA-2023-c406ba1ff6)
- 284325 Fedora Security Update for redis (FEDORA-2023-800612d23a)
- 355808 Amazon Linux Security Advisory for redis6 : ALAS2023-2023-291
- 356269 Amazon Linux Security Advisory for redis : ALASREDIS6-2023-002
- 505928 Alpine Linux Security Update for redis
- 6000455 Debian Security Update for redis (DSA 5610-1)
- 691209 Free Berkeley Software Distribution (FreeBSD) Security Update for redis (0e254b4a-1f37-11ee-a475-080027f5fec9)
- 907325 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (27477-1)