NULL pointer dereference in Redis - CVE-2022-24736
Published: April 29, 2022
Vulnerability identifier: #VU62692
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24736
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can use a specially crafted Lua script and perform a denial of service (DoS) attack.
Affected software
Redis
Amazon Linux AMI
Gentoo Linux
Oracle Linux
SUSE Manager Proxy
SUSE Manager Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
Fedora
IBM Cloud Pak for Multicloud Management
Qradar Advisor
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
IBM Planning Analytics Workspace
QRadar Assistant
redis
redis-debuginfo
redis-debugsource
redis6
redis6-doc
redis6-debuginfo
redis6-devel
redis6-debugsource
redis (Red Hat package)
dev-db/redis
Amazon Linux AMI
Gentoo Linux
Oracle Linux
SUSE Manager Proxy
SUSE Manager Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
Fedora
IBM Cloud Pak for Multicloud Management
Qradar Advisor
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
IBM Planning Analytics Workspace
QRadar Assistant
redis
redis-debuginfo
redis-debugsource
redis6
redis6-doc
redis6-debuginfo
redis6-devel
redis6-debugsource
redis (Red Hat package)
dev-db/redis
How to mitigate CVE-2022-24736
Install update from vendor's website.
Redis - addressed in versions 6.2.7, 7.0.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Qradar Advisor - update to 2.6.5
IBM Planning Analytics Workspace - update to 2.0.91
QRadar Assistant - update to 3.8.1
redis - update to 6.0.14-150200.6.11.1
redis-debuginfo - update to 6.0.14-150200.6.11.1
redis-debugsource - update to 6.0.14-150200.6.11.1
redis6 - update to 6.2.7-1
redis6-doc - update to 6.2.7-1
redis6 - update to 6.2.7-1
redis6-debuginfo - update to 6.2.7-1
redis6-devel - update to 6.2.7-1
redis6-debugsource - update to 6.2.7-1
redis (Red Hat package) - update to 6.2.7-1.el9
redis - addressed in versions 6.2.7-1.fc34, 6.2.7-1.fc35, 6.2.7-1.fc36
dev-db/redis - update to 7.0.5
redis - update to 7.2.7-1
redis-debuginfo - update to 7.2.7-1
redis-debugsource - update to 7.2.7-1
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.12.3
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.12.3
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Qradar Advisor - update to 2.6.5
IBM Planning Analytics Workspace - update to 2.0.91
QRadar Assistant - update to 3.8.1
redis - update to 6.0.14-150200.6.11.1
redis-debuginfo - update to 6.0.14-150200.6.11.1
redis-debugsource - update to 6.0.14-150200.6.11.1
redis6 - update to 6.2.7-1
redis6-doc - update to 6.2.7-1
redis6 - update to 6.2.7-1
redis6-debuginfo - update to 6.2.7-1
redis6-devel - update to 6.2.7-1
redis6-debugsource - update to 6.2.7-1
redis (Red Hat package) - update to 6.2.7-1.el9
redis - addressed in versions 6.2.7-1.fc34, 6.2.7-1.fc35, 6.2.7-1.fc36
dev-db/redis - update to 7.0.5
redis - update to 7.2.7-1
redis-debuginfo - update to 7.2.7-1
redis-debugsource - update to 7.2.7-1
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.12.3
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.12.3
External References
Related Security Bulletins
- Multiple vulnerabilities in Redis
- SUSE update for redis
- Gentoo update for Redis
- Red Hat Enterprise Linux 8 update for the redis:6 module
- Red Hat Enterprise Linux 9 update for redis
- Multiple vulnerabilities in IBM Spectrum Protect Plus Container backup and restore for Kubernetes and OpenShift
- SUSE update for redis
- Multiple vulnerabilities in IBM QRadar Advisor With Watson App for IBM QRadar SIEM
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- openEuler update for redis6
- Amazon Linux AMI update for redis6
- Multiple vulnerabilities in IBM QRadar Assistant
- Fedora 34 update for redis
- Fedora 35 update for redis
- Fedora 36 update for redis
- openEuler update for redis