Integer overflow in Redis - CVE-2023-22458
Published: January 16, 2023 / Updated: January 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in HRANDFIELD and ZRANDMEMBER commands. A remote attacker can pass specially crafted input to the application, trigger an integer overflow and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Fedora
Qradar Advisor
EasyApache
redis
redis-debuginfo
redis-debugsource
redis-devel
redis-doc
dev-db/redis
Storage Protect Plus Container Agent
How to mitigate CVE-2023-22458
Qradar Advisor - update to 2.6.5
EasyApache - update to 4 2024-1-24
redis - update to 6.2.6-150400.3.11.1
redis-debuginfo - update to 6.2.6-150400.3.11.1
redis-debugsource - update to 6.2.6-150400.3.11.1
redis - addressed in versions 6.2.9-1.fc36, 6.2.10-1.fc36, 7.0.8-1.fc37
redis - update to 6.2.17-1.0.1
redis-devel - update to 6.2.17-1.0.1
redis-doc - update to 6.2.17-1.0.1
dev-db/redis - update to 7.2.4
Storage Protect Plus Container Agent - update to 10.1.12.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Redis
- SUSE update for redis
- Multiple vulnerabilities in IBM QRadar Advisor With Watson App for IBM QRadar SIEM
- Multiple vulnerabilities in IBM Spectrum Protect Plus Container
- Fedora 36 update for redis
- Fedora 37 update for redis
- Fedora 36 update for redis
- Multiple vulnerabilities in cPanel EasyApache
- Gentoo update for Redis
- Red Hat Enterprise Linux 8 update for the redis:6 module
- Anolis OS update for redis:6 module