QID 376213

Date Published: 2022-01-03

QID 376213: Redis Server Heap Overflow Vulnerability

Redis is an open-source, in-memory database that persists on disk.

Integer overflow that can lead to heap overflow in Redis-CLI, Redis-sentinel on some platforms and DoS vulnerability

Affected Versions:
Redis Server versions prior to 6.2.6, 6.0.16, 5.0.14

QID Detection Logic:(Authenticated)
This QID will find out the vulnerable version of Redis server.

Successful exploitation of this vulnerability may lead to heap overflow in redis-cli, redis-sentinel on some platforms.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to update to the latest patch version of Redis Server. For more information, please refer to Redis Security Advisory GHSA-f6pwRedis Security Advisory GHSA-833w

    CVEs related to QID 376213

    Software Advisories
    Advisory ID Software Component Link
    GHSA-833w URL Logo github.com/redis/redis/security/advisories/GHSA-833w-8v3m-8wwr
    GHSA-f6pw URL Logo github.com/redis/redis/security/advisories/GHSA-f6pw-v9gw-v64p