{"id":"CVE-2022-35977","summary":"Integer overflow in certain command arguments can drive Redis to OOM panic","details":"Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["BIT-keydb-2022-35977","BIT-redis-2022-35977","BIT-valkey-2022-35977","GHSA-mrcw-fhw9-fj8j"],"modified":"2026-08-08T08:39:03.830987Z","published":"2023-01-20T18:19:27.692Z","related":["ALSA-2025:0595","SUSE-SU-2023:0274-1","SUSE-SU-2023:0295-1","openSUSE-SU-2024:12619-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35977.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-190"]},"references":[{"type":"WEB","url":"https://github.com/redis/redis/releases/tag/6.0.17"},{"type":"WEB","url":"https://github.com/redis/redis/releases/tag/6.2.9"},{"type":"WEB","url":"https://github.com/redis/redis/releases/tag/7.0.8"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00031.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35977.json"},{"type":"ADVISORY","url":"https://github.com/redis/redis/security/advisories/GHSA-mrcw-fhw9-fj8j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35977"},{"type":"FIX","url":"https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/redis/redis","events":[{"introduced":"17dfd7cabbf7954f92b7a1243d4bb27fee5d4500"},{"fixed":"6ed4dc5052488ba88d2b759d494b2d8083a46206"},{"introduced":"445aa844b946a8f1bc21ac8554b44adb1ecb4018"},{"fixed":"137696d80811c25b918f7f543bcbe8c9c142f49d"},{"introduced":"d375595d5e3ae2e5c29e6c00a2dc3d60578fd9fc"},{"fixed":"1c75ab062d0cb1f3af57e39a399325b9e917e85f"},{"fixed":"1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7"}],"database_specific":{"cpe":"cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.0.0"},{"fixed":"6.0.17"},{"introduced":"6.2.0"},{"fixed":"6.2.9"},{"introduced":"7.0.0"},{"fixed":"7.0.8"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["6.0.16","6.2.8","7.0.7","7.0.6","7.0.5","6.2.7","7.0.4","7.0.3","7.0.2","7.0.1","7.0.0","6.2.6","6.2.5","6.0.15","6.0.14","6.2.4","6.2.3","6.0.13","6.2.2","6.0.12","6.2.1","6.2.0","6.0.11","6.0.10","6.0.9","6.0.8","6.0.7","6.0.6","6.0.5","6.0.4","6.0.3","6.0.2","6.0.1","6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-35977.json","vanir_signatures_modified":"2026-08-08T08:39:03Z","vanir_signatures":[{"digest":{"length":900,"function_hash":"116971469754088312332483466748933374376"},"id":"CVE-2022-35977-3c7c1097","signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7","target":{"file":"src/t_string.c","function":"appendCommand"},"deprecated":false},{"target":{"function":"sortCommandGeneric","file":"src/sort.c"},"deprecated":false,"digest":{"length":8263,"function_hash":"82540812152969398714332745819166932468"},"id":"CVE-2022-35977-41b235f1","signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7"},{"deprecated":false,"digest":{"function_hash":"32570897349986556830414094619646893432","length":239},"id":"CVE-2022-35977-56893ded","signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7","target":{"file":"src/t_string.c","function":"checkStringLength"}},{"digest":{"line_hashes":["186433087898035617545730220172496680738","203202165573339978193990582202674487602","275809988698162680246583166226838038027","73578043121461598977650673034568374077"],"threshold":0.9},"id":"CVE-2022-35977-98932803","signature_type":"Line","signature_version":"v1","source":"https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7","target":{"file":"src/sort.c"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7","target":{"file":"src/t_string.c"},"deprecated":false,"digest":{"line_hashes":["248180385824619824772464830981375391534","5067477213071492840981082149613366054","241977057241639579814068567037512555282","11990352999479870707193441629836517373","100447336807789972624732637466025117494","327100190278669955728844978483813395719","130387995228581962465477485279535845614","105722549271231642153270839899496344190","294730995467472452864721434981947207124","22245381654923832682850503174443857317","130387995228581962465477485279535845614","243453517739048749692954273661613904305","308503519468359129265766654248724425353","110330893842926084747435436159183528456","51326573103712825352618788220523467272","294796335562077490498565494534997136298","134636369608514298103990068146183492358","38595801910815835602387448741994528733"],"threshold":0.9},"id":"CVE-2022-35977-9ff164f5","signature_type":"Line"},{"target":{"file":"src/t_string.c","function":"setrangeCommand"},"deprecated":false,"digest":{"function_hash":"68994465711976581911670797757864833457","length":1288},"id":"CVE-2022-35977-f965c2e0","signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/1ec82e6e97e1db06a72ca505f9fbf6b981f31ef7"}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}