Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-41056

Redis is an in-memory database that persists on disk.

Technology

Redis

CVSS Score

8.1 / 10.0

Affected Versions

>=7.0.9 <7.0.15; >=7.2.0 <7.2.4

Upstream Fix

See upstream advisory

Published

January 10, 2024

OSSeva Coverage

Fixed upstream

Description

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.

Is your Redis deployment affected?

If you're running >=7.0.9 <7.0.15; >=7.2.0 <7.2.4, you need this patch. Book a discovery call to get covered.