Back

MEDIUM

Integer overflow in certain command arguments can drive Redis to OOM panic

Published Jan 20, 2023

Description

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

Remediation

No remediation recorded yet.

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jan 20, 2023
Updated Nov 3, 2025
Reserved Jul 15, 2022

CISA Vulnrichment

Updated Mar 10, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jan 17, 2023
Bugzilla 2163133

ENISA EUVD

Assigner GitHub_M
Published Jan 20, 2023
Updated Nov 3, 2025

GitHub

No data