CVE-2021-29478

HIGH

Redis 6.2.0-6.2.2 - Remote Code Execution via Integer Overflow in set-max-intset-entries

Title source: llm
STIX 2.1

Description

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentially result with remote code execution. Redis 6.0 and earlier are not directly affected by this issue. The problem is fixed in version 6.2.3. An additional workaround to mitigate the problem without patching the `redis-server` executable is to prevent users from modifying the `set-max-intset-entries` configuration parameter. This can be done using ACL to restrict unprivileged users from using the `CONFIG SET` command.

References (5)

Core 5
Core References
Product x_refsource_misc
https://redis.io/
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202107-20

Scores

CVSS v3 7.5
EPSS 0.0368
EPSS Percentile 88.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (3)
fedoraproject/fedora 33
fedoraproject/fedora 34
redislabs/redis 6.2.0 - 6.2.3
Published May 04, 2021
Tracked Since Feb 18, 2026