Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade redis | Mar 26, 2024 | Jul 19, 2022 |
| Debian | — | Upgrade redis | Jul 30, 2024 | Jul 19, 2022 |
| Freebsd | — | Upgrade redis | Nov 4, 2022 | Jul 18, 2022 |
| Gentoo Linux | — | Upgrade dev-db/redis. | Sep 30, 2022 | Jul 19, 2022 |
| Redislabs Redis | — | Upgrade RedisLabs Redis to version 7.0.4 | Oct 17, 2025 | Jul 19, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 19, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub