CVE-2022-24736

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-24736
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-24736.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-24736
Aliases
Related
Published
2022-04-27T20:15:09Z
Modified
2024-10-12T09:15:50.315991Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to SCRIPT LOAD and EVAL commands using ACL rules.

References

Affected packages

Alpine:v3.14 / redis

Package

Name
redis
Purl
pkg:apk/alpine/redis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.7-r0

Affected versions

2.*

2.4.14-r0
2.4.14-r1
2.4.14-r2
2.4.16-r0
2.6.16-r0
2.6.17-r0
2.8.9-r0
2.8.9-r1
2.8.9-r2
2.8.10-r0
2.8.11-r0
2.8.12-r0
2.8.13-r0
2.8.14-r0
2.8.17-r0
2.8.19-r0

3.*

3.0.0-r0
3.0.0-r1
3.0.1-r0
3.0.2-r0
3.0.3-r0
3.0.4-r0
3.0.5-r0
3.0.5-r1
3.0.6-r0
3.0.7-r0
3.0.7-r1
3.2.0-r0
3.2.1-r0
3.2.3-r0
3.2.4-r0
3.2.5-r0
3.2.7-r0
3.2.8-r0
3.2.9-r0

4.*

4.0.2-r0
4.0.2-r1
4.0.5-r0
4.0.6-r0
4.0.8-r0
4.0.9-r0
4.0.9-r1
4.0.9-r2
4.0.10-r0
4.0.10-r1
4.0.11-r0
4.0.12-r0
4.0.13-r0

5.*

5.0.4-r0
5.0.5-r0
5.0.7-r0
5.0.8-r0
5.0.9-r0

6.*

6.0.1-r0
6.0.4-r0
6.0.5-r0
6.0.9-r0
6.0.10-r0
6.2.0-r0
6.2.1-r0
6.2.2-r0
6.2.3-r0
6.2.4-r0
6.2.5-r0
6.2.6-r0

Alpine:v3.15 / redis

Package

Name
redis
Purl
pkg:apk/alpine/redis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.7-r0

Affected versions

2.*

2.4.14-r0
2.4.14-r1
2.4.14-r2
2.4.16-r0
2.6.16-r0
2.6.17-r0
2.8.9-r0
2.8.9-r1
2.8.9-r2
2.8.10-r0
2.8.11-r0
2.8.12-r0
2.8.13-r0
2.8.14-r0
2.8.17-r0
2.8.19-r0

3.*

3.0.0-r0
3.0.0-r1
3.0.1-r0
3.0.2-r0
3.0.3-r0
3.0.4-r0
3.0.5-r0
3.0.5-r1
3.0.6-r0
3.0.7-r0
3.0.7-r1
3.2.0-r0
3.2.1-r0
3.2.3-r0
3.2.4-r0
3.2.5-r0
3.2.7-r0
3.2.8-r0
3.2.9-r0

4.*

4.0.2-r0
4.0.2-r1
4.0.5-r0
4.0.6-r0
4.0.8-r0
4.0.9-r0
4.0.9-r1
4.0.9-r2
4.0.10-r0
4.0.10-r1
4.0.11-r0
4.0.12-r0
4.0.13-r0

5.*

5.0.4-r0
5.0.5-r0
5.0.7-r0
5.0.8-r0
5.0.9-r0

6.*

6.0.1-r0
6.0.4-r0
6.0.5-r0
6.0.9-r0
6.0.10-r0
6.2.0-r0
6.2.1-r0
6.2.2-r0
6.2.3-r0
6.2.4-r0
6.2.5-r0
6.2.6-r0

Alpine:v3.16 / redis

Package

Name
redis
Purl
pkg:apk/alpine/redis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.7-r0

Affected versions

2.*

2.4.14-r0
2.4.14-r1
2.4.14-r2
2.4.16-r0
2.6.16-r0
2.6.17-r0
2.8.9-r0
2.8.9-r1
2.8.9-r2
2.8.10-r0
2.8.11-r0
2.8.12-r0
2.8.13-r0
2.8.14-r0
2.8.17-r0
2.8.19-r0

3.*

3.0.0-r0
3.0.0-r1
3.0.1-r0
3.0.2-r0
3.0.3-r0
3.0.4-r0
3.0.5-r0
3.0.5-r1
3.0.6-r0
3.0.7-r0
3.0.7-r1
3.2.0-r0
3.2.1-r0
3.2.3-r0
3.2.4-r0
3.2.5-r0
3.2.7-r0
3.2.8-r0
3.2.9-r0

4.*

4.0.2-r0
4.0.2-r1
4.0.5-r0
4.0.6-r0
4.0.8-r0
4.0.9-r0
4.0.9-r1
4.0.9-r2
4.0.10-r0
4.0.10-r1
4.0.11-r0
4.0.12-r0
4.0.13-r0

5.*

5.0.4-r0
5.0.5-r0
5.0.7-r0
5.0.8-r0
5.0.9-r0

6.*

6.0.1-r0
6.0.4-r0
6.0.5-r0
6.0.9-r0
6.0.10-r0
6.2.0-r0
6.2.1-r0
6.2.2-r0
6.2.3-r0
6.2.4-r0
6.2.5-r0
6.2.6-r0

Alpine:v3.17 / redis

Package

Name
redis
Purl
pkg:apk/alpine/redis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.7-r0

Affected versions

2.*

2.4.14-r0
2.4.14-r1
2.4.14-r2
2.4.16-r0
2.6.16-r0
2.6.17-r0
2.8.9-r0
2.8.9-r1
2.8.9-r2
2.8.10-r0
2.8.11-r0
2.8.12-r0
2.8.13-r0
2.8.14-r0
2.8.17-r0
2.8.19-r0

3.*

3.0.0-r0
3.0.0-r1
3.0.1-r0
3.0.2-r0
3.0.3-r0
3.0.4-r0
3.0.5-r0
3.0.5-r1
3.0.6-r0
3.0.7-r0
3.0.7-r1
3.2.0-r0
3.2.1-r0
3.2.3-r0
3.2.4-r0
3.2.5-r0
3.2.7-r0
3.2.8-r0
3.2.9-r0

4.*

4.0.2-r0
4.0.2-r1
4.0.5-r0
4.0.6-r0
4.0.8-r0
4.0.9-r0
4.0.9-r1
4.0.9-r2
4.0.10-r0
4.0.10-r1
4.0.11-r0
4.0.12-r0
4.0.13-r0

5.*

5.0.4-r0
5.0.5-r0
5.0.7-r0
5.0.8-r0
5.0.9-r0

6.*

6.0.1-r0
6.0.4-r0
6.0.5-r0
6.0.9-r0
6.0.10-r0
6.2.0-r0
6.2.1-r0
6.2.2-r0
6.2.3-r0
6.2.4-r0
6.2.5-r0
6.2.6-r0

Alpine:v3.18 / redis

Package

Name
redis
Purl
pkg:apk/alpine/redis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.7-r0

Affected versions

2.*

2.4.14-r0
2.4.14-r1
2.4.14-r2
2.4.16-r0
2.6.16-r0
2.6.17-r0
2.8.9-r0
2.8.9-r1
2.8.9-r2
2.8.10-r0
2.8.11-r0
2.8.12-r0
2.8.13-r0
2.8.14-r0
2.8.17-r0
2.8.19-r0

3.*

3.0.0-r0
3.0.0-r1
3.0.1-r0
3.0.2-r0
3.0.3-r0
3.0.4-r0
3.0.5-r0
3.0.5-r1
3.0.6-r0
3.0.7-r0
3.0.7-r1
3.2.0-r0
3.2.1-r0
3.2.3-r0
3.2.4-r0
3.2.5-r0
3.2.7-r0
3.2.8-r0
3.2.9-r0

4.*

4.0.2-r0
4.0.2-r1
4.0.5-r0
4.0.6-r0
4.0.8-r0
4.0.9-r0
4.0.9-r1
4.0.9-r2
4.0.10-r0
4.0.10-r1
4.0.11-r0
4.0.12-r0
4.0.13-r0

5.*

5.0.4-r0
5.0.5-r0
5.0.7-r0
5.0.8-r0
5.0.9-r0

6.*

6.0.1-r0
6.0.4-r0
6.0.5-r0
6.0.9-r0
6.0.10-r0
6.2.0-r0
6.2.1-r0
6.2.2-r0
6.2.3-r0
6.2.4-r0
6.2.5-r0
6.2.6-r0

Alpine:v3.19 / redis

Package

Name
redis
Purl
pkg:apk/alpine/redis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.7-r0

Affected versions

2.*

2.4.14-r0
2.4.14-r1
2.4.14-r2
2.4.16-r0
2.6.16-r0
2.6.17-r0
2.8.9-r0
2.8.9-r1
2.8.9-r2
2.8.10-r0
2.8.11-r0
2.8.12-r0
2.8.13-r0
2.8.14-r0
2.8.17-r0
2.8.19-r0

3.*

3.0.0-r0
3.0.0-r1
3.0.1-r0
3.0.2-r0
3.0.3-r0
3.0.4-r0
3.0.5-r0
3.0.5-r1
3.0.6-r0
3.0.7-r0
3.0.7-r1
3.2.0-r0
3.2.1-r0
3.2.3-r0
3.2.4-r0
3.2.5-r0
3.2.7-r0
3.2.8-r0
3.2.9-r0

4.*

4.0.2-r0
4.0.2-r1
4.0.5-r0
4.0.6-r0
4.0.8-r0
4.0.9-r0
4.0.9-r1
4.0.9-r2
4.0.10-r0
4.0.10-r1
4.0.11-r0
4.0.12-r0
4.0.13-r0

5.*

5.0.4-r0
5.0.5-r0
5.0.7-r0
5.0.8-r0
5.0.9-r0

6.*

6.0.1-r0
6.0.4-r0
6.0.5-r0
6.0.9-r0
6.0.10-r0
6.2.0-r0
6.2.1-r0
6.2.2-r0
6.2.3-r0
6.2.4-r0
6.2.5-r0
6.2.6-r0

Debian:11 / redis

Package

Name
redis
Purl
pkg:deb/debian/redis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5:6.*

5:6.0.15-1
5:6.0.16-1~bpo10+1
5:6.0.16-1~bpo11+1
5:6.0.16-1
5:6.0.16-1+deb11u1
5:6.0.16-1+deb11u2
5:6.0.16-1+deb11u3
5:6.0.16-2~bpo11+1
5:6.0.16-2
5:6.0.16-3
5:6.0.16-4~bpo11+1
5:6.0.16-4
5:6.2~rc1-1
5:6.2~rc1-2
5:6.2~rc1-3
5:6.2~rc2-1
5:6.2~rc2-2
5:6.2~rc3-1
5:6.2.0-1
5:6.2.1-1
5:6.2.2-1
5:6.2.3-1
5:6.2.4-1
5:6.2.5-1
5:6.2.5-2
5:6.2.5-3
5:6.2.5-4
5:6.2.6-1

5:7.*

5:7.0~rc1-1
5:7.0~rc2-1
5:7.0~rc2-2
5:7.0~rc3-1
5:7.0.0-1
5:7.0.1-1
5:7.0.1-2
5:7.0.1-3
5:7.0.1-4
5:7.0.2-1
5:7.0.2-2
5:7.0.3-1
5:7.0.4-1~bpo11+1
5:7.0.4-1
5:7.0.5-1~bpo11+1
5:7.0.5-1
5:7.0.7-1~bpo11+1
5:7.0.7-1
5:7.0.8-1
5:7.0.8-2
5:7.0.8-3
5:7.0.8-4
5:7.0.9-1
5:7.0.10-1~bpo11+1
5:7.0.10-1
5:7.0.11-1
5:7.0.12-1
5:7.0.12-2
5:7.0.13-1
5:7.0.13-2
5:7.0.14-1
5:7.0.14-2
5:7.0.15-1~deb12u1
5:7.0.15-1
5:7.0.15-2
5:7.2~rc1-1
5:7.2-rc2-1
5:7.2-rc3-1
5:7.2.0-1
5:7.2.0-2
5:7.2.1-1
5:7.2.1-2
5:7.2.2-1
5:7.2.2-2
5:7.2.3-1
5:7.2.4-1
5:7.2.5-1
5:7.2.5-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / redis

Package

Name
redis
Purl
pkg:deb/debian/redis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5:7.0.1-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / redis

Package

Name
redis
Purl
pkg:deb/debian/redis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5:7.0.1-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/redis/redis

Affected ranges

Type
GIT
Repo
https://github.com/redis/redis
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.3.6

2.*

2.2-alpha0
2.2-alpha1
2.2-alpha2
2.2-alpha3
2.2-alpha4
2.2-alpha5
2.2-alpha6
2.2.0-rc1
2.3-alpha0

3.*

3.0-alpha0

6.*

6.2-rc1
6.2-rc2
6.2-rc3
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6

v1.*

v1.3.10
v1.3.11
v1.3.12
v1.3.7
v1.3.8
v1.3.9

v2.*

v2.0.0-rc1
v2.1.1-watch

Other

vm-playpen
with-deprecated-diskstore