NULL pointer dereference in Redis - CVE-2022-24736

 

NULL pointer dereference in Redis - CVE-2022-24736

Published: April 29, 2022


Vulnerability identifier: #VU62692
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24736
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error. A remote attacker can use a specially crafted Lua script and perform a denial of service (DoS) attack.


Affected software

Redis
Amazon Linux AMI
Gentoo Linux
Oracle Linux
SUSE Manager Proxy
SUSE Manager Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
Fedora
IBM Cloud Pak for Multicloud Management
Qradar Advisor
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
IBM Planning Analytics Workspace
QRadar Assistant
redis
redis-debuginfo
redis-debugsource
redis6
redis6-doc
redis6-debuginfo
redis6-devel
redis6-debugsource
redis (Red Hat package)
dev-db/redis

How to mitigate CVE-2022-24736

Install update from vendor's website.

Redis - addressed in versions 6.2.7, 7.0.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Qradar Advisor - update to 2.6.5
IBM Planning Analytics Workspace - update to 2.0.91
QRadar Assistant - update to 3.8.1
redis - update to 6.0.14-150200.6.11.1
redis-debuginfo - update to 6.0.14-150200.6.11.1
redis-debugsource - update to 6.0.14-150200.6.11.1
redis6 - update to 6.2.7-1
redis6-doc - update to 6.2.7-1
redis6 - update to 6.2.7-1
redis6-debuginfo - update to 6.2.7-1
redis6-devel - update to 6.2.7-1
redis6-debugsource - update to 6.2.7-1
redis (Red Hat package) - update to 6.2.7-1.el9
redis - addressed in versions 6.2.7-1.fc34, 6.2.7-1.fc35, 6.2.7-1.fc36
dev-db/redis - update to 7.0.5
redis - update to 7.2.7-1
redis-debuginfo - update to 7.2.7-1
redis-debugsource - update to 7.2.7-1
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.12.3
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.12.3

External References

Related Security Bulletins