Low severity3.3NVD Advisory· Published Apr 27, 2022· Updated Jun 17, 2026
CVE-2022-24736
CVE-2022-24736
Description
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to SCRIPT LOAD and EVAL commands using ACL rules.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
25- cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_operations_monitor:4.3:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:communications_operations_monitor:4.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_operations_monitor:4.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_operations_monitor:5.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- osv-coords11 versionspkg:bitnami/keydbpkg:bitnami/redispkg:bitnami/valkeypkg:rpm/almalinux/redispkg:rpm/almalinux/redis-develpkg:rpm/almalinux/redis-docpkg:rpm/opensuse/redis&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/redis&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/redis&distro=openSUSE%20Tumbleweedpkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4
< 6.2.7+ 10 more
- (no CPE)range: < 6.2.7
- (no CPE)range: < 6.2.7
- (no CPE)range: < 6.2.7
- (no CPE)range: < 6.2.7-1.module_el8.7.0+3288+a82c1b48
- (no CPE)range: < 6.2.7-1.module_el8.7.0+3288+a82c1b48
- (no CPE)range: < 6.2.7-1.module_el8.7.0+3288+a82c1b48
- (no CPE)range: < 6.0.14-150200.6.11.1
- (no CPE)range: < 6.2.6-150400.3.3.7
- (no CPE)range: < 6.2.7-1.1
- (no CPE)range: < 6.0.14-150200.6.11.1
- (no CPE)range: < 6.2.6-150400.3.3.7
Patches
Vulnerability mechanics
References
10- github.com/redis/redis/security/advisories/GHSA-3qpw-7686-5984nvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpujul2022.htmlnvdPatchThird Party Advisory
- github.com/redis/redis/pull/10651nvdExploitThird Party Advisory
- github.com/redis/redis/releases/tag/6.2.7nvdRelease NotesThird Party Advisory
- github.com/redis/redis/releases/tag/7.0.0nvdRelease NotesThird Party Advisory
- security.gentoo.org/glsa/202209-17nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20220715-0003/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4ZK3675DGHVVDOFLJN7WX6YYH27GPMK/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VPYKSG7LKUJGVM2P72EHXKVRVRWHLORX/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WSTPUCAPBRHIFPSCOURR4OYX4E2OISAF/nvd
News mentions
0No linked articles in our index yet.