Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflow
Published Sep 23, 2022
9.8
CRITICALCVSS 3.1
EPSS 3.91%
Description
Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. This has been patched in Redis version 7.0.5. No known workarounds exist.
Affected products
-
Affected
- ≥ 7.0.0, < 7.0.5
Configuration 2
- 37
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/search-api-rhel8
Not affected
Red Hat Ansible Automation Platform 1.2
ansible-tower
Not affected
Red Hat Enterprise Linux 8
redis:6/redis
Not affected
Red Hat Enterprise Linux 9
redis
Not affected
Red Hat Fuse 7
redis
Not affected
Red Hat OpenStack Platform 13 (Queens)
redis
Not affected
Red Hat Quay 3
quay/quay-rhel8
Not affected
Red Hat Software Collections
rh-redis6-redis
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-api-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 1.2 | ansible-tower | Not affected | n/a |
| Red Hat Enterprise Linux 8 | redis:6/redis | Not affected | n/a |
| Red Hat Enterprise Linux 9 | redis | Not affected | n/a |
| Red Hat Fuse 7 | redis | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | redis | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | n/a |
| Red Hat Software Collections | rh-redis6-redis | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-35951 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2129701 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38797 Advisory
- https://github.com/redis/redis/security/advisories/GHSA-5gc4-76rx-22c9 Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A7INCOOFPPEAKNDBZU3TIZJPYXBULI2C/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-35951
- https://security.gentoo.org/glsa/202209-17 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20221020-0005/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-35951
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-35951 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2129701 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38797 | Advisory | |
| https://github.com/redis/redis/security/advisories/GHSA-5gc4-76rx-22c9 | Third Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A7INCOOFPPEAKNDBZU3TIZJPYXBULI2C/ | vendor-advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-35951 | ||
| https://security.gentoo.org/glsa/202209-17 | vendor-advisoryThird Party Advisory | |
| https://security.netapp.com/advisory/ntap-20221020-0005/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-35951 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data