{"id":"CVE-2024-25115","summary":"RedisBloom heap buffer overflow in CF.LOADCHUNK command","details":"RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.\n","aliases":["GHSA-w583-p2wh-4vj5"],"modified":"2026-08-12T15:15:54.462161Z","published":"2024-04-09T17:31:48.469Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/25xxx/CVE-2024-25115.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-120","CWE-122"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/25xxx/CVE-2024-25115.json"},{"type":"ADVISORY","url":"https://github.com/RedisBloom/RedisBloom/security/advisories/GHSA-w583-p2wh-4vj5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-25115"},{"type":"FIX","url":"https://github.com/RedisBloom/RedisBloom/commit/2f3b38394515fc6c9b130679bcd2435a796a49ad"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/redisbloom/redisbloom","events":[{"introduced":"baaee2dcecd1620799f9c7421dc657a27605a58d"},{"introduced":"0"},{"fixed":"bf84550c7d69b1b09f71d3ced308a7dfa7755286"},{"fixed":"36f53902b88d44530169fad7a881098b49ec8ee9"},{"fixed":"2f3b38394515fc6c9b130679bcd2435a796a49ad"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.4.7"},{"introduced":"2.5.0"},{"fixed":"2.6.10"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.6.9","v2.4.6","v2.6.8","v2.6.7","v2.6.5","v2.6.4","v2.6.3","v2.6.2","v2.6.1","v2.6.0","v2.4.5","v2.4.4","v2.4.3","v2.4.2","v2.4.1","v2.2.15","v2.0.3","v2.0.2","v2.0.1","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25115.json","vanir_signatures_modified":"2026-08-12T15:15:54Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/redisbloom/redisbloom/commit/2f3b38394515fc6c9b130679bcd2435a796a49ad","target":{"function":"CF_LoadEncodedChunk","file":"src/cf.c"},"deprecated":false,"digest":{"function_hash":"222243657635475658158603756236319369890","length":462},"id":"CVE-2024-25115-18801ec4","signature_type":"Function"},{"source":"https://github.com/redisbloom/redisbloom/commit/2f3b38394515fc6c9b130679bcd2435a796a49ad","target":{"file":"src/rebloom.c"},"deprecated":false,"digest":{"line_hashes":["116773953083172112896772184897939493551","308675992998803694801403149214540030862","21525716778001374164422979156413344839","192573559682853538099737964554336421367"],"threshold":0.9},"id":"CVE-2024-25115-2d3518cd","signature_type":"Line","signature_version":"v1"},{"digest":{"line_hashes":["267835960315856362022184875683151344701","93800031665719646591568624615999853982","51635030512611179200121448625426365713","299016108154084953226456680945481863857","22631816522298920735362489410373136305","185293111709477217294567683738526545459","179136555385557963914178264817035903663"],"threshold":0.9},"id":"CVE-2024-25115-300dfb6d","signature_type":"Line","signature_version":"v1","source":"https://github.com/redisbloom/redisbloom/commit/2f3b38394515fc6c9b130679bcd2435a796a49ad","target":{"file":"src/cf.c"},"deprecated":false},{"digest":{"function_hash":"35390843466424765521476027153180986635","length":1006},"id":"CVE-2024-25115-9fd78c71","signature_type":"Function","signature_version":"v1","source":"https://github.com/redisbloom/redisbloom/commit/2f3b38394515fc6c9b130679bcd2435a796a49ad","target":{"file":"src/rebloom.c","function":"CFScanDump_RedisCommand"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}