CVE-2023-41056

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
10/01/2024
Last modified:
23/02/2024

Description

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* 7.0.9 (including) 7.0.15 (excluding)
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.4 (excluding)
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*