Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted SETRANGE
and SORT(_RO)
commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2:2.8.4-2ubuntu0.2+esm3", "binary_name": "redis-server" }, { "binary_version": "2:2.8.4-2ubuntu0.2+esm3", "binary_name": "redis-server-dbgsym" }, { "binary_version": "2:2.8.4-2ubuntu0.2+esm3", "binary_name": "redis-tools" }, { "binary_version": "2:2.8.4-2ubuntu0.2+esm3", "binary_name": "redis-tools-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2:3.0.6-1ubuntu0.4+esm2", "binary_name": "redis-sentinel" }, { "binary_version": "2:3.0.6-1ubuntu0.4+esm2", "binary_name": "redis-server" }, { "binary_version": "2:3.0.6-1ubuntu0.4+esm2", "binary_name": "redis-server-dbgsym" }, { "binary_version": "2:3.0.6-1ubuntu0.4+esm2", "binary_name": "redis-tools" }, { "binary_version": "2:3.0.6-1ubuntu0.4+esm2", "binary_name": "redis-tools-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "5:4.0.9-1ubuntu0.2+esm4", "binary_name": "redis" }, { "binary_version": "5:4.0.9-1ubuntu0.2+esm4", "binary_name": "redis-sentinel" }, { "binary_version": "5:4.0.9-1ubuntu0.2+esm4", "binary_name": "redis-server" }, { "binary_version": "5:4.0.9-1ubuntu0.2+esm4", "binary_name": "redis-tools" }, { "binary_version": "5:4.0.9-1ubuntu0.2+esm4", "binary_name": "redis-tools-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "5:5.0.7-2ubuntu0.1+esm2", "binary_name": "redis" }, { "binary_version": "5:5.0.7-2ubuntu0.1+esm2", "binary_name": "redis-sentinel" }, { "binary_version": "5:5.0.7-2ubuntu0.1+esm2", "binary_name": "redis-server" }, { "binary_version": "5:5.0.7-2ubuntu0.1+esm2", "binary_name": "redis-tools" }, { "binary_version": "5:5.0.7-2ubuntu0.1+esm2", "binary_name": "redis-tools-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "5:6.0.16-1ubuntu1+esm1", "binary_name": "redis" }, { "binary_version": "5:6.0.16-1ubuntu1+esm1", "binary_name": "redis-sentinel" }, { "binary_version": "5:6.0.16-1ubuntu1+esm1", "binary_name": "redis-server" }, { "binary_version": "5:6.0.16-1ubuntu1+esm1", "binary_name": "redis-tools" }, { "binary_version": "5:6.0.16-1ubuntu1+esm1", "binary_name": "redis-tools-dbgsym" } ] }