Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.
{ "binaries": [ { "binary_name": "redis", "binary_version": "5:7.0.15-1ubuntu0.24.04.1" }, { "binary_name": "redis-sentinel", "binary_version": "5:7.0.15-1ubuntu0.24.04.1" }, { "binary_name": "redis-server", "binary_version": "5:7.0.15-1ubuntu0.24.04.1" }, { "binary_name": "redis-tools", "binary_version": "5:7.0.15-1ubuntu0.24.04.1" }, { "binary_name": "redis-tools-dbgsym", "binary_version": "5:7.0.15-1ubuntu0.24.04.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "valkey-redis-compat", "binary_version": "7.2.8+dfsg1-0ubuntu0.24.04.2" }, { "binary_name": "valkey-sentinel", "binary_version": "7.2.8+dfsg1-0ubuntu0.24.04.2" }, { "binary_name": "valkey-server", "binary_version": "7.2.8+dfsg1-0ubuntu0.24.04.2" }, { "binary_name": "valkey-tools", "binary_version": "7.2.8+dfsg1-0ubuntu0.24.04.2" }, { "binary_name": "valkey-tools-dbgsym", "binary_version": "7.2.8+dfsg1-0ubuntu0.24.04.2" } ], "availability": "No subscription required" }