CVE-2021-32626: Specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result with heap corruption and potentially remote code execution. CVE-2021-32627: An integer overflow bug in Redis 5.0 or newer can be exploited to corrupt the heap and potentially result with remote code execution. CVE-2021-32628: An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remote code execution. CVE-2021-32672: When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. CVE-2021-32675: When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of elements (in the multi-bulk header) and size of each element (in the bulk header). ...
Read the Full Advisory
- https://bugs.mageia.org/show_bug.cgi?id=29552
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VL5KXFN3ATM7IIM7Q4O4PWTSRGZ5744Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HTYQ5ZF37HNGTZWVNJD3VXP7I6MEEF42/
- https://www.cve.org/CVERecord?id=CVE-2021-32626
- https://www.cve.org/CVERecord?id=CVE-2021-32627
- https://www.cve.org/CVERecord?id=CVE-2021-32628
- https://www.cve.org/CVERecord?id=CVE-2021-32672
- https://www.cve.org/CVERecord?id=CVE-2021-32675
- https://www.cve.org/CVERecord?id=CVE-2021-32687
- https://www.cve.org/CVERecord?id=CVE-2021-32762
- https://www.cve.org/CVERecord?id=CVE-2021-41099
- 8/core/redis-6.0.16-1.mga8
Get the latest Linux and open source security news straight to your inbox.