CVE-2023-41056
published 2024-01-10CVE-2023-41056: Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to…
PriorityP352high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.58%
83.6th percentile
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | redis | < redis 5:7.0.15-1~deb12u1 (bookworm) | redis 5:7.0.15-1~deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redis | redis | — | — |
| redis | redis | — | — |
| redis | redis | >= 0 < 5:7.0.15-1~deb12u1 | 5:7.0.15-1~deb12u1 |
| redis | redis | >= 0 < 5:7.0.15-1 | 5:7.0.15-1 |
| redis | redis | >= 0 < 5:7.0.15-1 | 5:7.0.15-1 |
| redis | redis | >= 7.0.9 < 7.0.15 | 7.0.15 |
| redis | redis | >= 7.2.0 < 7.2.4 | 7.2.4 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (Redis) — CVE-2023-41056
vendor_oracle·2024-04-15·CVSS 8.1
CVE-2023-41056 [HIGH] Oracle Oracle Communications Risk Matrix: Third Party (Redis) — CVE-2023-41056
Oracle Oracle Communications Risk Matrix: Third Party (Redis) vulnerability
CVE: CVE-2023-41056
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Red Hat
redis: Heap Buffer Overflow may lead to potential remote code execution
vendor_redhat·2024-01-09·CVSS 8.1
CVE-2023-41056 [HIGH] CWE-122 redis: Heap Buffer Overflow may lead to potential remote code execution
redis: Heap Buffer Overflow may lead to potential remote code execution
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
A flaw was found in Redis. When processing a certain sequence of payloads, Redis may incorrectly handle the resizing of memory buffers, leading to a heap-based buffer overflow, potentially resulting in a denial of service or remote code execution.
Statement: The redis package, as shipped with Red Hat Enterprise Linux 8, 9, and RHSCL is not affected by this vulnerability because the vulnerable code was introduced in a newer version of redis. However, the r
Debian
CVE-2023-41056: redis - Redis is an in-memory database that persists on disk. Redis incorrectly handles ...
vendor_debian·2023·CVSS 8.1
CVE-2023-41056 [HIGH] CVE-2023-41056: redis - Redis is an in-memory database that persists on disk. Redis incorrectly handles ...
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Scope: local
bookworm: resolved (fixed in 5:7.0.15-1~deb12u1)
bullseye: resolved
forky: resolved (fixed in 5:7.0.15-1)
sid: resolved (fixed in 5:7.0.15-1)
trixie: resolved (fixed in 5:7.0.15-1)
OSV
CVE-2023-41056: Redis is an in-memory database that persists on disk
osv·2024-01-10·CVSS 8.1
CVE-2023-41056 [HIGH] CVE-2023-41056: Redis is an in-memory database that persists on disk
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-41056 redis: Heap Buffer Overflow may lead to potential remote code execution
bugzilla·2024-01-09·CVSS 8.1
CVE-2023-41056 [HIGH] CVE-2023-41056 redis: Heap Buffer Overflow may lead to potential remote code execution
CVE-2023-41056 redis: Heap Buffer Overflow may lead to potential remote code execution
In some cases, Redis may incorrectly handle resizing of memory buffers which can result in incorrect accounting of buffer sizes and lead to heap overflow and potential remote code execution.
Reference:
https://github.com/redis/redis/security/advisories/GHSA-xr47-pcmx-fq2m
Discussion:
Created redis tracking bugs for this issue:
Affects: epel-all [bug 2257456]
Affects: fedora-all [bug 2257455]
arXiv
ZeroDayBench: Evaluating LLM Agents on Unseen Zero-Day Vulnerabilities for Cyberdefense
arxiv_fulltext·2026-03-02
ZeroDayBench: Evaluating LLM Agents on Unseen Zero-Day Vulnerabilities for Cyberdefense
## Abstract
Large language models (LLMs) are increasingly being deployed as software engineering agents that autonomously contribute to repositories. A major benefit these agents present is their ability to find and patch security vulnerabilities in the codebases they oversee. To estimate the capability of agents in this domain, we introduce ZeroDayBench, a benchmark where LLM agents find and patch 22 novel critical vulnerabilities in open-source codebases. We focus our efforts on three popular frontier agentic LLMs: GPT-5.2, Claude Sonnet 4.5, and Grok 4.1. We find that frontier LLMs are not yet capable of autonomously solving our tasks and observe some behavioral patterns that suggest how these models can be improved in the domain of proactive cyberdefense.
## Introduction
Large langu
https://github.com/redis/redis/releases/tag/7.0.15https://github.com/redis/redis/releases/tag/7.2.4https://github.com/redis/redis/security/advisories/GHSA-xr47-pcmx-fq2mhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3JTGQJ2YLYB24B72I5B5H32YIMPVSWIT/https://lists.fedoraproject.org/archives/list/[email protected]/message/JTWHPLC3RI67VNRDOIXLDVNC5YMYBMQN/https://security.netapp.com/advisory/ntap-20240223-0003/https://github.com/redis/redis/releases/tag/7.0.15https://github.com/redis/redis/releases/tag/7.2.4https://github.com/redis/redis/security/advisories/GHSA-xr47-pcmx-fq2mhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3JTGQJ2YLYB24B72I5B5H32YIMPVSWIT/https://lists.fedoraproject.org/archives/list/[email protected]/message/JTWHPLC3RI67VNRDOIXLDVNC5YMYBMQN/https://security.netapp.com/advisory/ntap-20240223-0003/
2024-01-10
Published