PT-2019-3413 · Redis+5 · Redis+5

Published

2019-05-10

·

Updated

2026-05-18

·

CVE-2019-10192

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Redis versions 3.x through 3.2.12 Redis versions 4.x through 4.0.13 Redis versions 5.x through 5.0.3
Description The issue is related to a heap-buffer overflow vulnerability in the Redis hyperloglog data structure. It occurs when the SETRANGE command is used, allowing an attacker to corrupt the hyperloglog and write up to 3 bytes beyond the end of a heap-allocated buffer. This could enable a remote attacker to compromise data integrity, gain unauthorized access to sensitive information, and cause a denial of service.
Recommendations For Redis versions 3.x through 3.2.12, update to version 3.2.13 or later. For Redis versions 4.x through 4.0.13, update to version 4.0.14 or later. For Redis versions 5.x through 5.0.3, update to version 5.0.4 or later.

Fix

Heap Based Buffer Overflow

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1790
BDU:2019-03567
BDU:2019-03574
CESA-2019_2002
CLEANSTART-2026-AF35851
CLEANSTART-2026-AV02020
CLEANSTART-2026-BX37171
CLEANSTART-2026-CJ12020
CLEANSTART-2026-CU71831
CLEANSTART-2026-DI78859
CLEANSTART-2026-DL37890
CLEANSTART-2026-EL98096
CLEANSTART-2026-FR00621
CLEANSTART-2026-GJ95666
CLEANSTART-2026-IR62391
CLEANSTART-2026-JR53141
CLEANSTART-2026-JU65303
CLEANSTART-2026-LU31244
CLEANSTART-2026-MJ64494
CLEANSTART-2026-MZ27698
CLEANSTART-2026-NG71279
CLEANSTART-2026-PR27884
CLEANSTART-2026-QK48981
CLEANSTART-2026-QX99194
CLEANSTART-2026-RA63757
CLEANSTART-2026-RF40424
CLEANSTART-2026-SG88217
CLEANSTART-2026-UA95882
CLEANSTART-2026-WI17406
CLEANSTART-2026-XH31600
CLEANSTART-2026-YM75307
CVE-2019-10192
DLA-1850-1
DSA-4480-1
MGASA-2019-0226
RHSA-2019:1819
RHSA-2019:1860
RHSA-2019:2002
RHSA-2019:2506
RHSA-2019:2508
RHSA-2019:2621
RHSA-2019:2628
RHSA-2019:2630
RHSA-2019_2002
RLSA-2019:2002
USN-4061-1

Affected Products

Alt Linux
Centos
Red Hat
Redis
Rocky Linux
Ubuntu