PT-2019-3414 · Redis+5 · Redis+5

Lukas Braune

·

Published

2019-05-10

·

Updated

2026-05-18

·

CVE-2019-10193

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Redis versions 3.x before 3.2.13 Redis versions 4.x before 4.0.14 Redis versions 5.x before 5.0.4
Description The issue is related to a stack-buffer overflow vulnerability in the Redis hyperloglog data structure. It occurs when the SETRANGE command corrupts the hyperloglog data structure, allowing an attacker to add up to 12 bytes of information past the end of a stack-allocated buffer. This can be exploited by a remote attacker to compromise data integrity, gain unauthorized access to sensitive information, and cause a denial of service.
Recommendations For Redis versions 3.x before 3.2.13, update to version 3.2.13 or later. For Redis versions 4.x before 4.0.14, update to version 4.0.14 or later. For Redis versions 5.x before 5.0.4, update to version 5.0.4 or later. As a temporary workaround, consider restricting the use of the SETRANGE command to minimize the risk of exploitation.

Fix

Buffer Overflow

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1790
BDU:2019-03568
BDU:2019-03575
CESA-2019_2002
CLEANSTART-2026-AF35851
CLEANSTART-2026-AV02020
CLEANSTART-2026-BX37171
CLEANSTART-2026-CJ12020
CLEANSTART-2026-CU71831
CLEANSTART-2026-DI78859
CLEANSTART-2026-DL37890
CLEANSTART-2026-EL98096
CLEANSTART-2026-FR00621
CLEANSTART-2026-GJ95666
CLEANSTART-2026-IR62391
CLEANSTART-2026-JR53141
CLEANSTART-2026-JU65303
CLEANSTART-2026-LU31244
CLEANSTART-2026-MJ64494
CLEANSTART-2026-MZ27698
CLEANSTART-2026-NG71279
CLEANSTART-2026-PR27884
CLEANSTART-2026-QK48981
CLEANSTART-2026-QX99194
CLEANSTART-2026-RA63757
CLEANSTART-2026-RF40424
CLEANSTART-2026-SG88217
CLEANSTART-2026-UA95882
CLEANSTART-2026-WI17406
CLEANSTART-2026-XH31600
CLEANSTART-2026-YM75307
CVE-2019-10193
DSA-4480-1
MGASA-2019-0226
RHSA-2019:1819
RHSA-2019:2002
RHSA-2019_2002
RLSA-2019:2002
USN-4061-1

Affected Products

Alt Linux
Centos
Red Hat
Redis
Rocky Linux
Ubuntu