CVE-2022-36021
Summary
| CVE | CVE-2022-36021 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-01 16:15:00 UTC |
| Updated | 2023-11-07 03:49:00 UTC |
| Description | Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. The problem is fixed in Redis versions 6.0.18, 6.2.11, 7.0.9. |
Risk And Classification
Problem Types: CWE-407
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Redis string pattern matching can be abused to achieve Denial of Service · Advisory · redis/redis · GitHub | MISC | github.com | |
| String pattern matching had exponential time complexity on pathologic… · redis/redis@dcbfcb9 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181629 Debian Security Update for redis (DLA 3361-1)
- 182264 Debian Security Update for redis (CVE-2022-36021)
- 199978 Ubuntu Security Notification for Redis Vulnerabilities (USN-6531-1)
- 283772 Fedora Security Update for redis (FEDORA-2023-c685251667)
- 283773 Fedora Security Update for redis (FEDORA-2023-7a98e2d545)
- 284265 Fedora Security Update for redis (FEDORA-2023-b0768fba7b)
- 355142 Amazon Linux Security Advisory for redis6 : ALAS2023-2023-154
- 356171 Amazon Linux Security Advisory for redis : ALASREDIS6-2023-001
- 356510 Amazon Linux Security Advisory for redis : ALAS2REDIS6-2023-001
- 691077 Free Berkeley Software Distribution (FreeBSD) Security Update for redis (b17bce48-b7c6-11ed-b304-080027f5fec9)
- 753763 SUSE Enterprise Linux Security Update for redis (SUSE-SU-2023:0693-1)
- 905705 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13830)
- 905720 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13815)
- 906637 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13830-3)
- 906716 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (13815-1)