Integer Overflow or Wraparound Affecting redis package, versions <6.2.9-r0
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ALPINE314-REDIS-3243491
- published 20 Jan 2023
- disclosed 20 Jan 2023
Introduced: 20 Jan 2023
CVE-2022-35977 Open this link in a new tabHow to fix?
Upgrade Alpine:3.14
redis
to version 6.2.9-r0 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream redis
package and not the redis
package as distributed by Alpine
.
See How to fix?
for Alpine:3.14
relevant fixed versions and status.
Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted SETRANGE
and SORT(_RO)
commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability.
References
- https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7
- https://github.com/redis/redis/releases/tag/6.0.17
- https://github.com/redis/redis/releases/tag/6.2.9
- https://github.com/redis/redis/releases/tag/7.0.8
- https://github.com/redis/redis/security/advisories/GHSA-mrcw-fhw9-fj8j