CVE-2023-41056: Fedoraproject Fedora
High severity, CVSS 8.1. EPSS: 2.6% chance of exploitation in the next 30 days.
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Affected products
- Fedoraproject Fedora: version 38 only; version 39 only
- Redis Redis: from 7.0.9, before 7.0.15 (fixed in 7.0.15); from 7.2.0, before 7.2.4 (fixed in 7.2.4)
Published 2024-01-10. Last modified 2026-06-17.