CVE-2022-35977
Summary
| CVE | CVE-2022-35977 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-20 19:15:00 UTC |
| Updated | 2023-02-02 14:28:00 UTC |
| Description | Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Avoid integer overflows in SETRANGE and SORT (CVE-2022-35977) (#11720) · redis/redis@1ec82e6 · GitHub | MISC | github.com | |
| Release 7.0.8 · redis/redis · GitHub | MISC | github.com | |
| Release 6.2.9 · redis/redis · GitHub | MISC | github.com | |
| Release 6.0.17 · redis/redis · GitHub | MISC | github.com | |
| Integer overflow in the Redis SETRANGE and SORT/SORT_RO commands may result with false OOM panic · Advisory · redis/redis · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184359 Debian Security Update for redis (CVE-2022-35977)
- 199978 Ubuntu Security Notification for Redis Vulnerabilities (USN-6531-1)
- 283636 Fedora Security Update for redis (FEDORA-2023-fbfe7a6cfe)
- 283639 Fedora Security Update for redis (FEDORA-2023-68ae37fca3)
- 355142 Amazon Linux Security Advisory for redis6 : ALAS2023-2023-154
- 356171 Amazon Linux Security Advisory for redis : ALASREDIS6-2023-001
- 356510 Amazon Linux Security Advisory for redis : ALAS2REDIS6-2023-001
- 502644 Alpine Linux Security Update for redis
- 502645 Alpine Linux Security Update for redis
- 504360 Alpine Linux Security Update for redis
- 691029 Free Berkeley Software Distribution (FreeBSD) Security Update for redis (5fa68bd9-95d9-11ed-811a-080027f5fec9)
- 753621 SUSE Enterprise Linux Security Update for redis (SUSE-SU-2023:0274-1)
- 753641 SUSE Enterprise Linux Security Update for redis (SUSE-SU-2023:0295-1)
- 905327 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13125)
- 905351 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13146)
- 905578 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13146-1)
- 905605 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13125-1)
- 906598 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13146-3)
- 906671 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13125-3)
- 906788 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13146-5)