Integer overflow in Redis - CVE-2022-35977
Published: January 16, 2023 / Updated: January 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in SETRANGE and SORT/SORT_RO commands. A remote attacker can pass specially crafted input to the application, trigger an integer overflow and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Amazon Linux AMI
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
Qradar Advisor
EasyApache
redis-tools (Ubuntu package)
redis-server (Ubuntu package)
python-rq
redis-debuginfo
redis
redis-debugsource
redis6
redis-doc
redis-devel
dev-db/redis
Storage Protect Plus Container Agent
SmartFabric OS10
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2022-35977
Qradar Advisor - update to 2.6.5
redis-tools (Ubuntu package) - update to Ubuntu Pro
redis-server (Ubuntu package) - update to Ubuntu Pro
python-rq - update to 1.12.0-1.el8
EasyApache - update to 4 2024-1-24
redis-debuginfo - addressed in versions 6.0.14-150200.6.17.1, 6.2.6-150400.3.11.1
redis - addressed in versions 6.0.14-150200.6.17.1, 6.2.6-150400.3.11.1
redis-debugsource - addressed in versions 6.0.14-150200.6.17.1, 6.2.6-150400.3.11.1
redis - addressed in versions 6.2.9-1.fc36, 6.2.10-1.fc36, 7.0.8-1.fc37
redis6 - update to 6.2.11-1
redis-doc - update to 6.2.17-1.0.1
redis-devel - update to 6.2.17-1.0.1
redis - update to 6.2.17-1.0.1
dev-db/redis - update to 7.2.4
redis - update to 7.2.7-1
redis-debuginfo - update to 7.2.7-1
redis-debugsource - update to 7.2.7-1
Storage Protect Plus Container Agent - update to 10.1.12.6
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.12, 23.0.12
External References
Related Security Bulletins
- Multiple vulnerabilities in Redis
- SUSE update for redis
- SUSE update for redis
- Multiple vulnerabilities in IBM QRadar Advisor With Watson App for IBM QRadar SIEM
- Multiple vulnerabilities in IBM Spectrum Protect Plus Container
- Fedora 36 update for redis
- Fedora 37 update for redis
- Fedora 36 update for redis
- Fedora EPEL 8 update for python-rq
- Ubuntu update for redis
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in cPanel EasyApache
- Amazon Linux AMI update for redis6
- Gentoo update for Redis
- Red Hat Enterprise Linux 8 update for the redis:6 module
- openEuler update for redis
- Anolis OS update for redis:6 module
- Multiple vulnerabilities in Dell SmartFabric OS10
- Dell SmartFabric OS10 update for third-party components
- Dell Networking OS10 update for third-party components