Vulnerability CVE-2023-25155: Information

Description

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRANDMEMBER`, and `HRANDFIELD` commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. This problem affects all Redis versions. Patches were released in Redis version(s) 6.0.18, 6.2.11 and 7.0.9.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Published: March 2, 2023
Modified: March 10, 2023
Error type identifier: CWE-190

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
redissisyphus7.0.12-alt17.2.4-alt1.1ALT-PU-2023-4982-3327278Fixed
redissisyphus_e2k7.0.12-alt17.2.4-alt1.1ALT-PU-2023-5079-1-Fixed
redissisyphus_riscv647.2.0-alt0.port7.2.4-alt0.portALT-PU-2023-5217-1-Fixed
redisp106.2.13-alt16.2.14-alt1ALT-PU-2023-5230-3327639Fixed
redisp10_e2k6.2.13-alt16.2.14-alt1ALT-PU-2023-5452-1-Fixed
redisc10f16.2.13-alt16.2.13-alt1ALT-PU-2023-5229-3327640Fixed
redisc9f26.2.13-alt16.2.13-alt1ALT-PU-2023-5487-2328853Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
      Start including
      7.0.0
      End excliding
      7.0.9

      cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
      Start including
      6.2.0
      End excliding
      6.2.11

      cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
      End excliding
      6.0.18