SUSE-SU-2023:2122-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2122-1
SUSE-SU-2023:2122-1
Summary: Security update for redis
Details: This update for redis fixes the following issues: - CVE-2022-36021: Fixed possible integer overflow via specially crafted SRANDMEMBER, ZRANDMEMBER, and HRANDFIELD commands (bsc#1208790). - CVE-2023-28856: Fixed possible DoS when using HINCRBYFLOAT to create an hash field (bsc#1210548). - CVE-2023-25155: Fixed integer overflow in RAND commands that can lead to assertion (bsc#1208793).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232122-1/, https://bugzilla.suse.com/1208790, https://bugzilla.suse.com/1208793, https://bugzilla.suse.com/1210548, https://www.suse.com/security/cve/CVE-2022-36021, https://www.suse.com/security/cve/CVE-2023-25155, https://www.suse.com/security/cve/CVE-2023-28856
Affected packages
Package
Name: redis
Purl: pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
