CVE-2024-25116

Source
https://cve.org/CVERecord?id=CVE-2024-25116
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25116.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-25116
Aliases
  • GHSA-wrwq-cfrx-pmg4
Published
2024-04-09T17:35:08Z
Modified
2026-08-12T14:52:03Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Specially crafted CF.RESERVE command can lead to denial-of-service
Details

RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users can use the CF.RESERVE command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/25xxx/CVE-2024-25116.json"
}
References

Affected packages

Git / github.com/redisbloom/redisbloom

Affected ranges

Type
GIT
Repo
https://github.com/redisbloom/redisbloom
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.4.7"
        },
        {
            "introduced": "2.5.0"
        },
        {
            "fixed": "2.6.10"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.2.15
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.6.5
v2.6.7
v2.6.8
v2.6.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25116.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "153415020386162779225907443162050845205",
            "length": 1753
        },
        "id": "CVE-2024-25116-39fdf7c9",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/redisbloom/redisbloom/commit/61d980a429050637f1af9fe919a880800a824f2a",
        "target": {
            "file": "src/rebloom.c",
            "function": "cfInsertCommon"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "185392393138340217277226863066841876450",
            "length": 1833
        },
        "id": "CVE-2024-25116-4ebc33c4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/redisbloom/redisbloom/commit/61d980a429050637f1af9fe919a880800a824f2a",
        "target": {
            "file": "src/rebloom.c",
            "function": "CFReserve_RedisCommand"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "243010057716608570012849609245108196074",
            "length": 1349
        },
        "id": "CVE-2024-25116-6099587c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/redisbloom/redisbloom/commit/61d980a429050637f1af9fe919a880800a824f2a",
        "target": {
            "file": "src/rebloom.c",
            "function": "CFRdbLoad"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "35150882252351155525408165333404962204",
                "261164186667475559453769429532887562954",
                "283091487432106814185593275127895583047",
                "294495147522396428645336799173415638208",
                "30552737765970573967021921839907507040",
                "234761763605494639116055675841499593988",
                "109746849382894062182356500979046627380",
                "167593931499793890481138802473427324607",
                "331341740708077017974735545673287030592",
                "189226435309678874380386309420436559258",
                "26383261573547940987228378677572888210",
                "245963322289051637977247650526771331610",
                "22896410096302328337950667928147728210",
                "34433739489015720724279335831675776132",
                "210240867767419236905028677941201910097",
                "272072175793527924019131062240525850904",
                "144474234854787801241504298665904367342",
                "95347974454592870651870128600697628237",
                "16174377404020960252164768270952966835",
                "78768908067203613845141520077174807482",
                "11575743488410574528649941139805034439",
                "46484353156289029558893539692284348263",
                "244139587945181673543374075667091213920",
                "89920348895770297792675053289246819864",
                "129204347564020615283518068212889927141",
                "237779211588072481663622364902853768507",
                "308512999386062839096279042209613853591",
                "107990404030056990790398701523384697220",
                "330147737916734396396446449812316696028",
                "49253160322730918470749937605200041466",
                "10378124451513707636063151113348830691",
                "109706091224330000965282839073365222482",
                "226674219370201441533383243086315080840",
                "240180776690626239578654771945113615062",
                "277251012455351045933070312452924980314",
                "27974458412507093027261204050195461434",
                "233990193616506981742898709956981898264",
                "236537023244291620570810785016533039357",
                "285842830399445121240818067647748786595"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2024-25116-d1e10efe",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/redisbloom/redisbloom/commit/61d980a429050637f1af9fe919a880800a824f2a",
        "target": {
            "file": "src/rebloom.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T14:52:03Z"