CVE-2023-36824
In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, in some cases, trigger a heap overflow and result in reading random heap memory, heap corruption and potentially remote code execution.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 77.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, in some cases, trigger a heap overflow and result in reading random heap memory, heap corruption and potentially remote code execution. Several scenarios that may lead to authenticated users executing a specially crafted `COMMAND GETKEYS` or `COMMAND GETKEYSANDFLAGS`and authenticated users who were set with ACL rules that match key names, executing a specially crafted command that refers to a variadic list of key names. The vulnerability is patched in Redis 7.0.12.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 77.42% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-122, CWE-131, CWE-787
- Affected
- redis/redis · fedoraproject/fedora
- Source
- security-advisories@github.com
References
- https://github.com/redis/redis/releases/tag/7.0.12Release Notes
- https://github.com/redis/redis/security/advisories/GHSA-4cfx-h9gq-xpx3Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIF5MAGYARYUMRFK7PQI7HYXMK2HZE5T/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TDNNH2ONMVNBQ6LUIAOAGDNFPKXNST5K/Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230814-0009/Third Party Advisory
- https://github.com/redis/redis/releases/tag/7.0.12Release Notes
- https://github.com/redis/redis/security/advisories/GHSA-4cfx-h9gq-xpx3Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIF5MAGYARYUMRFK7PQI7HYXMK2HZE5T/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TDNNH2ONMVNBQ6LUIAOAGDNFPKXNST5K/Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230814-0009/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.