Rapid7

vulnerability

FreeBSD: VID-9b4806c1-257f-11ec-9db5-0800270512f4 (CVE-2021-32687): redis -- multiple vulnerabilities

Severity
6
CVSS
(AV:N/AC:M/Au:S/C:P/I:P/A:P)
Published
Oct 5, 2021
Added
Nov 4, 2022
Modified
Jun 15, 2026

Description

Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the heap or trigger remote code execution. The vulnerability involves changing the default set-max-intset-entries configuration parameter to a very large value and constructing specially crafted commands to manipulate sets. The problem is fixed in Redis versions 6.2.6, 6.0.16 and 5.0.14. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from modifying the set-max-intset-entries configuration parameter. This can be done using ACL to restrict unprivileged users from using the CONFIG SET command.

Solutions

freebsd-upgrade-package-redis-develfreebsd-upgrade-package-redisfreebsd-upgrade-package-redis6freebsd-upgrade-package-redis5
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.