CVE-2022-35951

HIGH

Redis 7.0.0-7.0.4 - Integer Overflow via XAUTOCLAIM COUNT Argument

Title source: llm
STIX 2.1

Description

Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. This has been patched in Redis version 7.0.5. No known workarounds exist.

Scores

CVSS v3 7.0
EPSS 0.3694
EPSS Percentile 97.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-190
Status published
Products (2)
fedoraproject/fedora 37
redis/redis 7.0.0 - 7.0.5
Published Sep 23, 2022
Tracked Since Feb 18, 2026