PT-2022-3071 · Redis+1 · Redis+1

Published

2022-06-22

·

Updated

2025-10-21

·

CVE-2022-33105

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Redis version 7.0
Description The issue is related to a memory leak via the streamGetEdgeID component. It is associated with insufficient input validation in the Redis database management system. Exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of data.
Recommendations For Redis version 7.0, consider disabling the streamGetEdgeID function as a temporary workaround until a patch is available. Restrict access to the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4982
ALT-PU-2025-11673
ALT-PU-2025-13204
BDU:2022-03741
BIT-KEYDB-2022-33105
BIT-REDIS-2022-33105
BIT-VALKEY-2022-33105
CVE-2022-33105

Affected Products

Alt Linux
Redis