{"id":"CVE-2023-28425","summary":"Specially crafted MSETNX command can lead to denial-of-service","details":"Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in Redis version 7.0.10.","aliases":["BIT-keydb-2023-28425","BIT-redis-2023-28425","BIT-valkey-2023-28425","GHSA-mvmm-4vq6-vw8c"],"modified":"2026-08-12T13:34:07.016067Z","published":"2023-03-20T19:03:37.983Z","related":["SUSE-SU-2023:2925-1","openSUSE-SU-2024:12874-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28425.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-77"]},"references":[{"type":"WEB","url":"https://github.com/redis/redis/releases/tag/7.0.10"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28425.json"},{"type":"ADVISORY","url":"https://github.com/redis/redis/security/advisories/GHSA-mvmm-4vq6-vw8c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28425"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230413-0005/"},{"type":"FIX","url":"https://github.com/redis/redis/commit/48e0d4788434833b47892fe9f3d91be7687f25c9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/redis/redis","events":[{"introduced":"1c75ab062d0cb1f3af57e39a399325b9e917e85f"},{"fixed":"f651708a19b4fc8137eec13180fcea39e68fb284"},{"fixed":"48e0d4788434833b47892fe9f3d91be7687f25c9"}],"database_specific":{"cpe":"cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.0.8"},{"fixed":"7.0.10"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["7.0.9","7.0.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-28425.json","vanir_signatures_modified":"2026-08-12T13:34:07Z","vanir_signatures":[{"source":"https://github.com/redis/redis/commit/48e0d4788434833b47892fe9f3d91be7687f25c9","target":{"file":"src/t_string.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["182441475610501642605671073658934620783","241118046475951381955528223975032974221","334050752336779759007882543621550513946","237595142625563674270053138787378263237","35732086388463942058125361226889985808","288024238321528681936570854698871010674","75253573151739155987044230693324820391","272495540065890920143075774673935492458","295587121365029152918241275795065942476","187887677250993250430183502289061114315","62206514092654505229129687247055069622","54822411206008816447706005567200311080"]},"id":"CVE-2023-28425-3e580eb8","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/48e0d4788434833b47892fe9f3d91be7687f25c9","target":{"file":"src/t_string.c","function":"msetGenericCommand"},"deprecated":false,"digest":{"function_hash":"105846752632493924986120124577450657934","length":761},"id":"CVE-2023-28425-e9185a57"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}