Bug 1218646 (CVE-2023-41056) - VUL-0: CVE-2023-41056: redis7: incorrectly handle resizing of memory buffers
Summary: VUL-0: CVE-2023-41056: redis7: incorrectly handle resizing of memory buffers
Status: RESOLVED FIXED
Alias: CVE-2023-41056
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/390478/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-41056:8.8:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-01-09 13:09 UTC by Alexander Bergmann
Modified: 2024-05-17 08:45 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2024-01-09 13:09:26 UTC
Redis released new versions (7.0.15 and 7.2.4) that fix a security issue.

Security fixes

(CVE-2023-41056) In some cases, Redis may incorrectly handle resizing of memory buffers which can result in incorrect accounting of buffer sizes and lead to heap overflow and potential remote code execution.

References:
https://github.com/redis/redis/releases/tag/7.2.4
https://github.com/redis/redis/releases/tag/7.0.15
Comment 1 Alexander Bergmann 2024-01-15 16:02:02 UTC
According to the security advisory our SLE-15-SP5 version is not affected:

https://github.com/redis/redis/security/advisories/GHSA-xr47-pcmx-fq2m

Impact
------
In some cases, Redis may incorrectly handle resizing of memory buffers which can result in incorrect accounting of buffer sizes and lead to heap overflow and potential remote code execution.

The problem exists in Redis 7.0.9 or newer (including 7.2.x).

Patches
-------
The problem is fixed in Redis 7.0.15 and 7.2.4.


SUSE/openSUSE versions:
SUSE:SLE-15-SP5    redis-7.0.8
openSUSE:Factory   redis-7.2.4
Comment 4 Andrea Mattiazzo 2024-05-17 08:45:50 UTC
All done, closing.