Recently, we have noticed that Redis has released security-patched versions. A crafted stream RESTORE payload can cause two consumers to share the same NACK, triggering a use-after-free vulnerability which may lead to Remote Code Execution.
Redis is an open-source, network-supported, memory-based, distributed, and optionally persistent key-value pair storage database. If you are a Redis user, check your system and implement timely security hardening.
Reference:
https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4
https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3
important
(Severity: low, medium, important, and critical)
Redis 6.2.22
Redis 7.2.14
Redis 7.4.9
Redis 8.2.7
Redis 8.4.4
Redis 8.6.4
Redis >= 6.2.23
Redis >= 7.2.15
Redis >= 7.4.10
Redis >= 8.2.8
Redis >= 8.4.5
Redis >= 8.6.5
Redis >= 8.8.0
This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.
https://github.com/redis/redis/releases
Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.
Get more professional support at any time
Contact Us