Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 8: 2023-0156 Critical Redis Crash Risk Due to Invalid Hash Field

mageia
Calendar Grey April 24, 2023
Dist Mageia Esm H88
The latest redis updates for Mageia address a severe security vulnerability that could lead to system crashes via a malformed hash field.
Authenticated users can use the HINCRBYFLOAT command to create an invalid hash field that will crash Redis on access

Summary

Authenticated users can use the HINCRBYFLOAT command to create an invalid hash field that will crash Redis on access. (CVE-2023-28856)

References

- https://bugs.mageia.org/show_bug.cgi?id=31809

- https://github.com/redis/redis/releases/tag/6.0.19

- https://www.cve.org/CVERecord?id=CVE-2023-28856

Resolution

SRPMS

- 8/core/redis-6.0.19-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 24 Apr 2023
URL: https://advisories.mageia.org/MGASA-2023-0156.html
Type: security
CVE: CVE-2023-28856

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here