{"id":"SUSE-SU-2021:3772-1","summary":"Security update for redis","details":"This update for redis fixes the following issues:\n\t  \n- CVE-2021-32627: Fixed integer to heap buffer overflows with streams (bsc#1191305).\n- CVE-2021-32628: Fixed integer to heap buffer overflows handling ziplist-encoded data types (bsc#1191305).\n- CVE-2021-32687: Fixed integer to heap buffer overflow with intsets (bsc#1191302).\n- CVE-2021-32762: Fixed integer to heap buffer overflow issue in redis-cli and redis-sentinel (bsc#1191300).\n- CVE-2021-32626: Fixed heap buffer overflow caused by specially crafted Lua scripts (bsc#1191306).\n- CVE-2021-32672: Fixed random heap reading issue with Lua Debugger (bsc#1191304).\n- CVE-2021-32675: Fixed Denial Of Service when processing RESP request payloads with a large number of elements on many connections (bsc#1191303).\n- CVE-2021-41099: Fixed integer to heap buffer overflow handling certain string commands and network payloads (bsc#1191299).\n","modified":"2025-05-02T04:10:41.075488Z","published":"2021-11-23T14:48:08Z","related":["CVE-2021-32626","CVE-2021-32627","CVE-2021-32628","CVE-2021-32672","CVE-2021-32675","CVE-2021-32687","CVE-2021-32762","CVE-2021-41099"],"upstream":["CVE-2021-32626","CVE-2021-32627","CVE-2021-32628","CVE-2021-32672","CVE-2021-32675","CVE-2021-32687","CVE-2021-32762","CVE-2021-41099"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20213772-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191299"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191300"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191302"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191303"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191304"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191305"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191306"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32626"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32627"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32672"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32762"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-41099"}],"affected":[{"package":{"name":"redis","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP2","purl":"pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.14-6.8.1"}]}],"ecosystem_specific":{"binaries":[{"redis":"6.0.14-6.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:3772-1.json"}},{"package":{"name":"redis","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP3","purl":"pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.14-6.8.1"}]}],"ecosystem_specific":{"binaries":[{"redis":"6.0.14-6.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:3772-1.json"}}],"schema_version":"1.7.3"}