Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of elements (in the multi-bulk header) and size of each element (in the bulk header). An attacker delivering specially crafted requests over multiple connections can cause the server to allocate significant amount of memory. Because the same parsing mechanism is used to handle authentication requests, this vulnerability can also be exploited by unauthenticated users. The problem is fixed in Redis versions 6.2.6, 6.0.16 and 5.0.14. An additional workaround to mitigate this problem without patching the redis-server executable is to block access to prevent unauthenticated users from connecting to Redis. This can be done in different ways: Using network access control tools like firewalls, iptables, security groups, etc. or Enabling TLS and requiring users to authenticate using client side certificates.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
21 Nov 2024, 06:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/redis/redis/commit/5674b0057ff2903d43eaff802017eddf37c360f8 - Patch, Third Party Advisory | |
References | () https://github.com/redis/redis/security/advisories/GHSA-f6pw-v9gw-v64p - Third Party Advisory | |
References | () https://lists.apache.org/thread.html/ra603ff6e04549d7f290f61f9b11e2d2e4dba693b05ff053f4ec6bc47%40%3Cnotifications.geode.apache.org%3E - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HTYQ5ZF37HNGTZWVNJD3VXP7I6MEEF42/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VL5KXFN3ATM7IIM7Q4O4PWTSRGZ5744Z/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WR5WKJWXD4D6S3DJCZ56V74ESLTDQRAB/ - | |
References | () https://security.gentoo.org/glsa/202209-17 - Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20211104-0003/ - Third Party Advisory | |
References | () https://www.debian.org/security/2021/dsa-5001 - Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory |
07 Nov 2023, 03:35
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2021-10-04 18:15
Updated : 2024-11-21 06:07
NVD link : CVE-2021-32675
Mitre link : CVE-2021-32675
CVE.ORG link : CVE-2021-32675
JSON object : View
Products Affected
redis
- redis
netapp
- management_services_for_netapp_hci
- management_services_for_element_software
oracle
- communications_operations_monitor
debian
- debian_linux
fedoraproject
- fedora
CWE
CWE-770
Allocation of Resources Without Limits or Throttling