Unrated severityNVD Advisory· Published Jan 10, 2024· Updated Jun 17, 2025
Redis vulnerable to integer overflow in certain payloads
CVE-2023-41056
Description
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/redis/redis/releases/tag/7.0.15mitrex_refsource_MISC
- github.com/redis/redis/releases/tag/7.2.4mitrex_refsource_MISC
- github.com/redis/redis/security/advisories/GHSA-xr47-pcmx-fq2mmitrex_refsource_CONFIRM
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JTGQJ2YLYB24B72I5B5H32YIMPVSWIT/mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JTWHPLC3RI67VNRDOIXLDVNC5YMYBMQN/mitre
- security.netapp.com/advisory/ntap-20240223-0003/mitre
News mentions
0No linked articles in our index yet.