Input validation error in RedisBloom - CVE-2024-25116
Published: April 9, 2024 / Updated: July 22, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the CF.RESERVE command when processing a specially crafted command. A local user can send a specially crafted CF.RESERVE command to cause a denial of service.
The issue can trigger a runtime assertion and terminate the Redis server process.