Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade redis | Mar 26, 2024 | Jan 10, 2024 |
| Amazon Linux Ami 2 | — | Upgrade redis-docUpgrade redis-debuginfoUpgrade redisUpgrade redis-devel | Feb 7, 2024 | Jan 10, 2024 |
| Amazon_linux_2023 | — | Upgrade redis6-debugsourceUpgrade redis6Upgrade redis6-develUpgrade redis6-docUpgrade redis6-debuginfo | Feb 17, 2025 | Jan 9, 2024 |
| Debian | — | Upgrade redis | Feb 5, 2024 | Jan 10, 2024 |
| Gentoo Linux | — | Upgrade dev-db/redis. | Aug 8, 2024 | Jan 10, 2024 |
| Redislabs Redis | — | Upgrade RedisLabs Redis to version 7.0.15Upgrade RedisLabs Redis to version 7.2.4 | Oct 17, 2025 | Jan 10, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub