Integer overflow in Redis - CVE-2023-22458

 

Integer overflow in Redis - CVE-2023-22458

Published: January 16, 2023 / Updated: January 20, 2023


Vulnerability identifier: #VU71193
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22458
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow in HRANDFIELD and ZRANDMEMBER commands. A remote attacker can pass specially crafted input to the application, trigger an integer overflow and perform a denial of service (DoS) attack.


Affected software

Redis
Gentoo Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Fedora
Qradar Advisor
EasyApache
redis
redis-debuginfo
redis-debugsource
redis-devel
redis-doc
dev-db/redis
Storage Protect Plus Container Agent

How to mitigate CVE-2023-22458

Install updates from vendor's website.

Redis - addressed in versions 6.2.9, 7.0.8
Qradar Advisor - update to 2.6.5
EasyApache - update to 4 2024-1-24
redis - update to 6.2.6-150400.3.11.1
redis-debuginfo - update to 6.2.6-150400.3.11.1
redis-debugsource - update to 6.2.6-150400.3.11.1
redis - addressed in versions 6.2.9-1.fc36, 6.2.10-1.fc36, 7.0.8-1.fc37
redis - update to 6.2.17-1.0.1
redis-devel - update to 6.2.17-1.0.1
redis-doc - update to 6.2.17-1.0.1
dev-db/redis - update to 7.2.4
Storage Protect Plus Container Agent - update to 10.1.12.6

External References

Related Security Bulletins