Severity
8.1
High severity
Details
- CVSS score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Overview
About vulnerability
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.Details
- Affected product:
- AlmaLinux 9.2 ESU , Alpine Linux 3.22 , Debian 12 , Debian 13 , TuxCare 9.6 ESU
- Affected packages:
- redis @ 6:6.2.21 (+4 more)