Reachable Assertion in Redis - CVE-2023-28425
Published: March 20, 2023 / Updated: March 22, 2023
Vulnerability identifier: #VU73836
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28425
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when handling the MSETNX command. A remote attacker can send a specially crafted MSETNX command and perform a denial of service (DoS) attack.
Affected software
Redis
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Server Applications Module
openSUSE Leap
Fedora
redis6
redis7
redis7-debuginfo
redis7-debugsource
redis
dev-db/redis
Storage Protect Plus Container Agent
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Server Applications Module
openSUSE Leap
Fedora
redis6
redis7
redis7-debuginfo
redis7-debugsource
redis
dev-db/redis
Storage Protect Plus Container Agent
How to mitigate CVE-2023-28425
Install updates from vendor's website.
Redis - update to 7.0.10
redis6 - update to 6.2.12-1
redis7 - update to 7.0.8-150500.3.3.1
redis7-debuginfo - update to 7.0.8-150500.3.3.1
redis7-debugsource - update to 7.0.8-150500.3.3.1
redis - addressed in versions 7.0.10-1.fc37, 7.0.10-1.fc38
dev-db/redis - update to 7.2.4
Storage Protect Plus Container Agent - update to 10.1.12.6
redis6 - update to 6.2.12-1
redis7 - update to 7.0.8-150500.3.3.1
redis7-debuginfo - update to 7.0.8-150500.3.3.1
redis7-debugsource - update to 7.0.8-150500.3.3.1
redis - addressed in versions 7.0.10-1.fc37, 7.0.10-1.fc38
dev-db/redis - update to 7.2.4
Storage Protect Plus Container Agent - update to 10.1.12.6