CVE-2023-41056
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 6.79%
- CWE
- CWE-762, CWE-190
- Published
- 2024-01-10
- Last modified
- 2026-03-13
Affected products
- redis redis
- redis redis
Weakness type
Related vulnerabilities
- CVE-2026-43622 — llama.cpp b1886–b7445 Double Free via llama-android.cpp
- CVE-2025-48431 — Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
- CVE-2025-11015 — OGRECave Ogre OgreSTBICodec.cpp encode mismatched memory management routines
- CVE-2025-48755 — In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).
- CVE-2025-47737 — lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero.
- CVE-2025-20189 — A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco...
- CVE-2024-4853 — Mismatched Memory Management Routines in editcap
- CVE-2024-2955 — Mismatched Memory Management Routines in Wireshark