Medium severity5.3NVD Advisory· Published Mar 31, 2021· Updated Jun 17, 2026
CVE-2021-3470
CVE-2021-3470
Description
A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users, who use jemalloc or glibc malloc.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:redislabs:redis:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:redislabs:redis:*:*:*:*:*:*:*:*range: <5.0.10
- cpe:2.3:a:redislabs:redis:6.2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:redislabs:redis:6.2.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:redislabs:redis:6.2.0:rc3:*:*:*:*:*:*
- (no CPE)range: <5.0.10, <6.0.9, <6.2.0
- (no CPE)range: redis 5.0.10, redis 6.0.9, redis 6.2.0
Patches
Vulnerability mechanics
References
1- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.