PT-2021-7752 · Redis+5 · Redis+5

Published

2021-10-04

·

Updated

2026-05-18

·

CVE-2021-32672

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Redis versions 3.2 through 6.2.5 Redis versions 3.2 through 6.0.15 Redis versions 3.2 through 5.0.13 can be simplified to: Redis versions 3.2 through 6.2.5
Description The issue affects Redis, an open source, in-memory database that persists on disk, when using the Redis Lua Debugger. Users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This can allow a remote attacker to access confidential data using a specially crafted request.
Recommendations For versions prior to 6.2.6, update to version 6.2.6 or later. For versions prior to 6.0.16, update to version 6.0.16 or later. For versions prior to 5.0.14, update to version 5.0.14 or later. As a temporary workaround, consider disabling the Lua debugging support until a patch is available.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3311
ALT-PU-2022-2429
ALT-PU-2023-4109
AZL-6847
BDU:2023-02451
BIT-KEYDB-2021-32672
BIT-REDIS-2021-32672
BIT-VALKEY-2021-32672
CLEANSTART-2026-AF35851
CLEANSTART-2026-AV02020
CLEANSTART-2026-BX37171
CLEANSTART-2026-CJ12020
CLEANSTART-2026-CU71831
CLEANSTART-2026-DI78859
CLEANSTART-2026-DL37890
CLEANSTART-2026-EL98096
CLEANSTART-2026-FR00621
CLEANSTART-2026-GJ95666
CLEANSTART-2026-IR62391
CLEANSTART-2026-JR53141
CLEANSTART-2026-JU65303
CLEANSTART-2026-LU31244
CLEANSTART-2026-MJ64494
CLEANSTART-2026-MZ27698
CLEANSTART-2026-NG71279
CLEANSTART-2026-PR27884
CLEANSTART-2026-QK48981
CLEANSTART-2026-QX99194
CLEANSTART-2026-RA63757
CLEANSTART-2026-RF40424
CLEANSTART-2026-SG88217
CLEANSTART-2026-UA95882
CLEANSTART-2026-WI17406
CLEANSTART-2026-XH31600
CLEANSTART-2026-YM75307
CVE-2021-32672
DLA-2810-1
DSA-5001-1
GHSA-9MJ9-XX53-QMXM
MGASA-2021-0483
OESA-2021-1394
OESA-2022-1866
OPENSUSE-SU-2021:3772-1
OPENSUSE-SU-2021_3772-1
OPENSUSE-SU-2024:11563-1
SUSE-SU-2021:3772-1
USN-5221-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Redis
Suse
Ubuntu