Medium severity5.5NVD Advisory· Published Apr 18, 2023· Updated Jun 17, 2026
CVE-2023-28856
CVE-2023-28856
Description
Redis is an open source, in-memory database that persists on disk. Authenticated users can use the HINCRBYFLOAT command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
32cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- osv-coords25 versionspkg:apk/chainguard/redis-6.2.10-benchmarkpkg:apk/chainguard/redis-6.2.10-clipkg:bitnami/keydbpkg:bitnami/redispkg:bitnami/valkeypkg:rpm/almalinux/redispkg:rpm/almalinux/redis-develpkg:rpm/almalinux/redis-docpkg:rpm/opensuse/redis&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/redis&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/redis7&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/redis&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/redis&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP3pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/redis&distro=SUSE%20Manager%20Proxy%204.2pkg:rpm/suse/redis&distro=SUSE%20Manager%20Server%204.2pkg:rpm/suse/redis7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP5
< 6.2.10-r40+ 24 more
- (no CPE)range: < 6.2.10-r40
- (no CPE)range: < 6.2.10-r40
- (no CPE)range: < 6.0.19
- (no CPE)range: < 6.0.19
- (no CPE)range: < 6.0.19
- (no CPE)range: < 6.2.17-1.module_el8.10.0+3946+3de613d5
- (no CPE)range: < 6.2.17-1.module_el8.10.0+3946+3de613d5
- (no CPE)range: < 6.2.17-1.module_el8.10.0+3946+3de613d5
- (no CPE)range: < 6.2.6-150400.3.19.1
- (no CPE)range: < 7.0.11-1.1
- (no CPE)range: < 7.0.8-150500.3.3.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.2.6-150400.3.19.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 6.0.14-150200.6.26.1
- (no CPE)range: < 7.0.8-150500.3.3.1
Patches
Vulnerability mechanics
References
8- github.com/redis/redis/commit/bc7fe41e5857a0854d524e2a63a028e9394d2a5cnvdPatch
- github.com/redis/redis/pull/11149nvdIssue TrackingPatch
- github.com/redis/redis/security/advisories/GHSA-hjv8-vjf6-wcr6nvdVendor Advisory
- lists.debian.org/debian-lts-announce/2023/04/msg00023.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/EQ4DJSO4DMR55AWK6OPVJH5UTEB35R2Z/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/LPUTH7NBQTZDVJWFNUD24ZCS6NDUFYS6/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/OQGKMKSQE67L32HE6W5EI2I2YKW5VWHI/nvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20230601-0007/nvd
News mentions
0No linked articles in our index yet.