Headline
CVE-2022-31144: Release 7.0.4 · redis/redis
Redis is an in-memory database that persists on disk. A specially crafted XAUTOCLAIM
command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.
Upgrade urgency: SECURITY, contains fixes to security issues.
Security Fixes:
- (CVE-2022-31144) A specially crafted XAUTOCLAIM command on a stream
key in a specific state may result with heap overflow, and potentially
remote code execution. The problem affects Redis versions 7.0.0 or newer.
Related news
Gentoo Linux Security Advisory 202209-17
Gentoo Linux Security Advisory 202209-17 - Multiple vulnerabilities have been found in Redis, the worst of which could result in arbitrary code execution. Versions less than 7.0.5 are affected.