{"id":"CVE-2021-31294","details":"Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.","aliases":["BIT-keydb-2021-31294","BIT-redis-2021-31294","BIT-valkey-2021-31294"],"modified":"2026-08-07T16:50:19.701988Z","published":"2023-07-15T23:15:09.203Z","references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230814-0007/"},{"type":"FIX","url":"https://github.com/redis/redis/commit/46f4ebbe842620f0976a36741a72482620aa4b48"},{"type":"FIX","url":"https://github.com/redis/redis/commit/6cbea7d29b5285692843bc1c351abba1a7ef326f"},{"type":"EVIDENCE","url":"https://github.com/redis/redis/issues/8712"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/redis/redis","events":[{"introduced":"0"},{"fixed":"445aa844b946a8f1bc21ac8554b44adb1ecb4018"},{"fixed":"46f4ebbe842620f0976a36741a72482620aa4b48"},{"fixed":"6cbea7d29b5285692843bc1c351abba1a7ef326f"}],"database_specific":{"cpe":"cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.2.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["6.2.2","6.2.1","6.2.0","6.2-rc3","6.2-rc2","6.2-rc1","2.3-alpha0","2.2.0-rc1","2.2-alpha6","2.2-alpha5","2.2-alpha4","2.2-alpha3","2.2-alpha2","2.2-alpha1","2.2-alpha0","v2.0.0-rc1","v2.1.1-watch","v1.3.11","v1.3.10","v1.3.9","v1.3.8","v1.3.7","1.3.6","vm-playpen"],"database_specific":{"vanir_signatures_modified":"2026-08-07T16:50:19Z","vanir_signatures":[{"source":"https://github.com/redis/redis/commit/46f4ebbe842620f0976a36741a72482620aa4b48","target":{"function":"processCommand","file":"src/server.c"},"deprecated":false,"digest":{"function_hash":"282123370244413014246199029746729897148","length":7030},"id":"CVE-2021-31294-4649935c","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/redis/redis/commit/6cbea7d29b5285692843bc1c351abba1a7ef326f","target":{"file":"src/server.c"},"deprecated":false,"digest":{"line_hashes":["276382160438463011791802486832098299543","81607497027349941400853452622911852480","174079452592190344646743064570921806917","22113432673264524511123880544413766800","159146439693756605255239566703403474960","308353159144754152971991578537313484920","215022253635914417357690862670091515120","68898065989528973432968670459207424448","145822087540847534025611738967447833776","75200904934883108131631146582879460284"],"threshold":0.9},"id":"CVE-2021-31294-987a7952"},{"deprecated":false,"digest":{"function_hash":"282123370244413014246199029746729897148","length":7030},"id":"CVE-2021-31294-afd6e43e","signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/6cbea7d29b5285692843bc1c351abba1a7ef326f","target":{"function":"processCommand","file":"src/server.c"}},{"deprecated":false,"digest":{"line_hashes":["276382160438463011791802486832098299543","81607497027349941400853452622911852480","174079452592190344646743064570921806917","22113432673264524511123880544413766800","159146439693756605255239566703403474960","308353159144754152971991578537313484920","215022253635914417357690862670091515120","68898065989528973432968670459207424448","145822087540847534025611738967447833776","75200904934883108131631146582879460284"],"threshold":0.9},"id":"CVE-2021-31294-e9048c40","signature_type":"Line","signature_version":"v1","source":"https://github.com/redis/redis/commit/46f4ebbe842620f0976a36741a72482620aa4b48","target":{"file":"src/server.c"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31294.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}