CVE-2021-29478
Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentially result with remote code execution. Redis 6.0 and earlier are not directly affected by this issue. The problem is fixed in version 6.2.3. An additional workaround to mitigate the problem without patching the `redis-server` executable is to prevent users from modifying the `set-max-intset-entries` configuration parameter. This can be done using ACL to restrict unprivileged users from using the `CONFIG SET` command.
EPSS 3.61% · 89.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redislabs | redis | 6.2.0 |
| fedoraproject | fedora | 33, 34 |
| redis | redis | >= 6.2.0, < 6.2.3 |
Timeline
- May 3, 2021 CVE Published
- May 5, 2021 EPSS Score
- Jul 8, 2021 EPSS Score
- Nov 10, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 11, 2022 EPSS Score
- Mar 14, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 15, 2022 EPSS Score
- Jul 18, 2022 EPSS Score
- Nov 19, 2022 EPSS Score
- Jan 20, 2023 EPSS Score
References
- https://redis.io/ url
- GLSA-202107-20 vendor-advisory
- https://github.com/redis/redis/security/advisories/GHSA-qh52-crrg-44g3 advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPWBIZXA67JFIB63W2CNVVILCGIC2ME5/ technical
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZJ6JGQ2ETZB2DWTQSGCOGG7EF3ILV4V/ technical