PT-2022-5226 · Redis+3 · Redis+3

Arkamar

·

Published

2022-10-21

·

Updated

2026-05-18

·

CVE-2022-3647

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Redis versions up to 6.2.7/7.0.5
Description A vulnerability was found in the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The complexity of an attack is rather high. The exploitability is told to be difficult. The real existence of this vulnerability is still doubted at the moment. The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred.
Recommendations Upgrading to version 6.2.8 and 7.0.6 is able to address this issue. It is recommended to apply a patch to fix this issue, the patch is identified as 0bf90d944313919eb8e63d3588bf63a367f020a3. As a temporary workaround, consider disabling the sigsegvHandler function until a patch is available.

Exploit

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-11325
BDU:2022-06489
BIT-KEYDB-2022-3647
BIT-REDIS-2022-3647
BIT-VALKEY-2022-3647
CLEANSTART-2026-AF35851
CLEANSTART-2026-AV02020
CLEANSTART-2026-BX37171
CLEANSTART-2026-CJ12020
CLEANSTART-2026-CU71831
CLEANSTART-2026-DI78859
CLEANSTART-2026-DL37890
CLEANSTART-2026-EL98096
CLEANSTART-2026-FR00621
CLEANSTART-2026-GJ95666
CLEANSTART-2026-IR62391
CLEANSTART-2026-JR53141
CLEANSTART-2026-JU65303
CLEANSTART-2026-LU31244
CLEANSTART-2026-MJ64494
CLEANSTART-2026-MZ27698
CLEANSTART-2026-NG71279
CLEANSTART-2026-PR27884
CLEANSTART-2026-QK48981
CLEANSTART-2026-QX99194
CLEANSTART-2026-RA63757
CLEANSTART-2026-RF40424
CLEANSTART-2026-SG88217
CLEANSTART-2026-UA95882
CLEANSTART-2026-WI17406
CLEANSTART-2026-XH31600
CLEANSTART-2026-YM75307
CVE-2022-3647
OESA-2025-1157
OPENSUSE-SU-2022_4168-1
OPENSUSE-SU-2022_4169-1
OPENSUSE-SU-2024:12468-1
ROSA-SA-2023-2174
SUSE-SU-2022:4168-1
SUSE-SU-2022:4169-1
SUSE-SU-2022_4168-1
SUSE-SU-2022_4169-1

Affected Products

Debian
Red Os
Redis
Suse