CVE-2022-35951
Summary
| CVE | CVE-2022-35951 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-23 04:15:00 UTC |
| Updated | 2023-11-07 03:49:00 UTC |
| Description | Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. This has been patched in Redis version 7.0.5. No known workarounds exist. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2022-35951 Redis Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Redis: Multiple Vulnerabilities (GLSA 202209-17) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 37 Update: redis-7.0.5-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Heap overflow in Redis 7.0 XAUTOCLAIM command's COUNT argument. · Advisory · redis/redis · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 37 Update: redis-7.0.5-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183583 Debian Security Update for redis (CVE-2022-35951)
- 502511 Alpine Linux Security Update for redis
- 504359 Alpine Linux Security Update for redis
- 690943 Free Berkeley Software Distribution (FreeBSD) Security Update for redis (f1f637d1-39eb-11ed-ab44-080027f5fec9)
- 710625 Gentoo Linux Redis Multiple Vulnerabilities (GLSA 202209-17)
- 904876 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (12417)
- 904994 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (12625)