Back to Vulnerability Directory
HIGHFixed upstream
CVE-2023-41056
Redis is an in-memory database that persists on disk.
Technology
Redis
CVSS Score
8.1 / 10.0
Affected Versions
>=7.0.9 <7.0.15; >=7.2.0 <7.2.4
Upstream Fix
See upstream advisory
Published
January 10, 2024
OSSeva Coverage
Fixed upstream
Description
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Is your Redis deployment affected?
If you're running >=7.0.9 <7.0.15; >=7.2.0 <7.2.4, you need this patch. Book a discovery call to get covered.