Impact
Executing a XAUTOCLAIM command on a stream key in a specific state, with a specially crafted COUNT argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. The problem affects Redis versions 7.0.0 or newer.
Patches
The problem is fixed in Redis version 7.0.5.
Credits
This problem was identified by Xion (SeungHyun Lee) of KAIST GoN.
For more information
If you have any questions or comments about this advisory:
Impact
Executing a
XAUTOCLAIMcommand on a stream key in a specific state, with a specially craftedCOUNTargument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. The problem affects Redis versions 7.0.0 or newer.Patches
The problem is fixed in Redis version 7.0.5.
Credits
This problem was identified by Xion (SeungHyun Lee) of KAIST GoN.
For more information
If you have any questions or comments about this advisory: