Integer overflow in certain command arguments can drive Redis to OOM panic
Published Jan 20, 2023
5.5
MEDIUMCVSS 3.1
EPSS 13.45%
Description
Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected products
-
Affected
- < 6.0.17
- ≥ 6.2, < 6.2.9
- ≥ 7.0, < 7.0.8
No data.
Red Hat Enterprise Linux 8
redis:6-8100020250113083959.489197e6
Fixed · RHSA-2025:0595
Red Hat 3scale API Management Platform 2
3scale-amp-backend-container
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/search-api-rhel8
Not affected
Red Hat Ansible Automation Platform 1.2
ansible-tower
Will not fix
Red Hat Enterprise Linux 8
redis
Will not fix
Red Hat Enterprise Linux 9
redis
Not affected
Red Hat Fuse 7
redis
Not affected
Red Hat OpenStack Platform 13 (Queens)
redis
Out of support scope
Red Hat Quay 3
quay/quay-rhel8
Will not fix
Red Hat Satellite 6
satellite:el8/rubygem-gitlab-sidekiq-fetcher
Not affected
Red Hat Satellite 6
tfm-rubygem-gitlab-sidekiq-fetcher
Not affected
Red Hat Software Collections
rh-redis6-redis
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | redis:6-8100020250113083959.489197e6 | Fixed | RHSA-2025:0595 |
| Red Hat 3scale API Management Platform 2 | 3scale-amp-backend-container | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-api-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 1.2 | ansible-tower | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | redis | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | redis | Not affected | n/a |
| Red Hat Fuse 7 | redis | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | redis | Out of support scope | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Will not fix | n/a |
| Red Hat Satellite 6 | satellite:el8/rubygem-gitlab-sidekiq-fetcher | Not affected | n/a |
| Red Hat Satellite 6 | tfm-rubygem-gitlab-sidekiq-fetcher | Not affected | n/a |
| Red Hat Software Collections | rh-redis6-redis | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-35977 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2163133 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38804 Advisory
- https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7 x_refsource_MISCPatchThird Party Advisory
- https://github.com/redis/redis/releases/tag/6.0.17 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/redis/redis/releases/tag/6.2.9 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/redis/redis/releases/tag/7.0.8 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/redis/redis/security/advisories/GHSA-mrcw-fhw9-fj8j x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/11/msg00031.html
- https://nvd.nist.gov/vuln/detail/CVE-2022-35977
- https://www.cve.org/CVERecord?id=CVE-2022-35977
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-35977 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2163133 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38804 | Advisory | |
| https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/redis/redis/releases/tag/6.0.17 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/redis/redis/releases/tag/6.2.9 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/redis/redis/releases/tag/7.0.8 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/redis/redis/security/advisories/GHSA-mrcw-fhw9-fj8j | x_refsource_CONFIRMThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2024/11/msg00031.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-35977 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-35977 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data