CVE-2023-41056

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

History

23 Feb 2024, 16:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240223-0003/ -

22 Jan 2024, 18:58

Type Values Removed Values Added
First Time Fedoraproject fedora
Fedoraproject
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.1
CPE cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JTGQJ2YLYB24B72I5B5H32YIMPVSWIT/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JTGQJ2YLYB24B72I5B5H32YIMPVSWIT/ - Mailing List, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JTWHPLC3RI67VNRDOIXLDVNC5YMYBMQN/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JTWHPLC3RI67VNRDOIXLDVNC5YMYBMQN/ - Mailing List, Third Party Advisory

18 Jan 2024, 03:15

Type Values Removed Values Added
CPE cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JTGQJ2YLYB24B72I5B5H32YIMPVSWIT/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JTWHPLC3RI67VNRDOIXLDVNC5YMYBMQN/ -
References () https://github.com/redis/redis/releases/tag/7.0.15 - () https://github.com/redis/redis/releases/tag/7.0.15 - Release Notes
References () https://github.com/redis/redis/releases/tag/7.2.4 - () https://github.com/redis/redis/releases/tag/7.2.4 - Release Notes
References () https://github.com/redis/redis/security/advisories/GHSA-xr47-pcmx-fq2m - () https://github.com/redis/redis/security/advisories/GHSA-xr47-pcmx-fq2m - Vendor Advisory
First Time Redis
Redis redis
Summary
  • (es) Redis es una base de datos en memoria que persiste en el disco. Redis maneja incorrectamente el cambio de tamaño de los búferes de memoria, lo que puede provocar un desbordamiento de enteros que provoca un desbordamiento del montón y una posible ejecución remota de código. Este problema se solucionó en las versiones 7.0.15 y 7.2.4.
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 9.8

10 Jan 2024, 16:59

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-10 16:15

Updated : 2024-02-23 16:15


NVD link : CVE-2023-41056

Mitre link : CVE-2023-41056

CVE.ORG link : CVE-2023-41056


JSON object : View

Products Affected

fedoraproject

  • fedora

redis

  • redis
CWE
CWE-190

Integer Overflow or Wraparound

CWE-762

Mismatched Memory Management Routines