VulnerabilityModified
CVE-2022-31144
A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution.
HIGH 8.8EPSS 3.22%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.22% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-122, CWE-787
- Affected
- redis/redis
- Source
- security-advisories@github.com
References
- https://github.com/redis/redis/releases/tag/7.0.4Release Notes, Third Party Advisory
- https://github.com/redis/redis/security/advisories/GHSA-96f7-42fg-2jrhThird Party Advisory
- https://security.gentoo.org/glsa/202209-17Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220909-0002/Third Party Advisory
- https://github.com/redis/redis/releases/tag/7.0.4Release Notes, Third Party Advisory
- https://github.com/redis/redis/security/advisories/GHSA-96f7-42fg-2jrhThird Party Advisory
- https://security.gentoo.org/glsa/202209-17Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220909-0002/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.