Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves modifying the default ziplist configuration parameters (hash-max-ziplist-entries, hash-max-ziplist-value, zset-max-ziplist-entries or zset-max-ziplist-value) to a very large value, and then constructing specially crafted commands to create very large ziplists. The problem is fixed in Redis versions 6.2.6, 6.0.16, 5.0.14. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from modifying the above configuration parameters. This can be done using ACL to restrict unprivileged users from using the CONFIG SET command.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-redisalma-upgrade-redis-develalma-upgrade-redis-doc | May 4, 2022 | Oct 4, 2021 | |
| Alpine Linux | alpine-linux-upgrade-redis | Mar 26, 2024 | Oct 4, 2021 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-redisamazon-linux-ami-2-upgrade-redis-debuginfoamazon-linux-ami-2-upgrade-redis-develamazon-linux-ami-2-upgrade-redis-doc | Sep 28, 2023 | Oct 4, 2021 | |
| Centos_linux | — | centos-upgrade-rediscentos-upgrade-redis-debuginfocentos-upgrade-redis-debugsourcecentos-upgrade-redis-develcentos-upgrade-redis-doc | Oct 20, 2021 | Oct 19, 2021 |
| Debian | debian-upgrade-redis | Nov 29, 2021 | Oct 4, 2021 | |
| Freebsd | freebsd-upgrade-package-redis-develfreebsd-upgrade-package-redisfreebsd-upgrade-package-redis6freebsd-upgrade-package-redis5 | Nov 4, 2022 | Oct 5, 2021 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-db-redis | Sep 30, 2022 | Oct 4, 2021 | |
| Oracle_linux | — | oracle-linux-upgrade-redisoracle-linux-upgrade-redis-develoracle-linux-upgrade-redis-doc | Oct 20, 2021 | Oct 4, 2021 |
| Redhat_linux | redhat-upgrade-redisredhat-upgrade-redis-debuginforedhat-upgrade-redis-debugsourceredhat-upgrade-redis-develredhat-upgrade-redis-doc | Oct 20, 2021 | Oct 19, 2021 | |
| Redislabs Redis | redislabs-redis-upgrade-5_0_14redislabs-redis-upgrade-6_0_16redislabs-redis-upgrade-6_2_6 | Oct 17, 2025 | Oct 4, 2021 | |
| Rocky_linux | rocky-upgrade-redisrocky-upgrade-redis-debuginforocky-upgrade-redis-debugsourcerocky-upgrade-redis-devel | Mar 12, 2024 | Oct 4, 2021 | |
| Suse | — | suse-upgrade-redis | Nov 24, 2021 | Oct 4, 2021 |
| Ubuntu | ubuntu-pro-upgrade-redisubuntu-pro-upgrade-redis-serverubuntu-pro-upgrade-redis-tools | Mar 22, 2023 | Oct 4, 2021 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Oct 4, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub