PT-2022-5226 · Redis+3 · Redis+3
Arkamar
·
Published
2022-10-21
·
Updated
2026-05-18
·
CVE-2022-3647
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Redis versions up to 6.2.7/7.0.5
Description
A vulnerability was found in the function
sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The complexity of an attack is rather high. The exploitability is told to be difficult. The real existence of this vulnerability is still doubted at the moment. The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred.Recommendations
Upgrading to version 6.2.8 and 7.0.6 is able to address this issue.
It is recommended to apply a patch to fix this issue, the patch is identified as 0bf90d944313919eb8e63d3588bf63a367f020a3.
As a temporary workaround, consider disabling the
sigsegvHandler function until a patch is available.Exploit
Fix
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Red Os
Redis
Suse