CVE-2023-25155
Summary
| CVE | CVE-2023-25155 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-02 04:15:00 UTC |
| Updated | 2023-03-10 05:02:00 UTC |
| Description | Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRANDMEMBER`, and `HRANDFIELD` commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. This problem affects all Redis versions. Patches were released in Redis version(s) 6.0.18, 6.2.11 and 7.0.9. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Integer Overflow in several Redis commands can lead to denial of service. · Advisory · redis/redis · GitHub | MISC | github.com | |
| Integer Overflow in RAND commands can lead to assertion (CVE-2023-25155) · redis/redis@2a2a582 · GitHub | MISC | github.com | |
| Release 7.0.9 · redis/redis · GitHub | MISC | github.com | |
| Release 6.2.11 · redis/redis · GitHub | MISC | github.com | |
| Release 6.0.18 · redis/redis · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182725 Debian Security Update for redis (CVE-2023-25155)
- 199978 Ubuntu Security Notification for Redis Vulnerabilities (USN-6531-1)
- 283772 Fedora Security Update for redis (FEDORA-2023-c685251667)
- 283773 Fedora Security Update for redis (FEDORA-2023-7a98e2d545)
- 284265 Fedora Security Update for redis (FEDORA-2023-b0768fba7b)
- 355142 Amazon Linux Security Advisory for redis6 : ALAS2023-2023-154
- 356171 Amazon Linux Security Advisory for redis : ALASREDIS6-2023-001
- 356510 Amazon Linux Security Advisory for redis : ALAS2REDIS6-2023-001
- 691077 Free Berkeley Software Distribution (FreeBSD) Security Update for redis (b17bce48-b7c6-11ed-b304-080027f5fec9)
- 753763 SUSE Enterprise Linux Security Update for redis (SUSE-SU-2023:0693-1)
- 906691 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (25354-3)
- 906695 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (25344-1)