CVE-2021-32672: Vulnerability in Lua Debugger in Redis
A flaw was found in redis. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer, potentially leading to an information disclosure.
Other sources
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/redisto a version that resolves this vulnerability.Fixed in 5:5.0.14-1+deb10u2Fixed in 5:5.0.14-1+deb10u5Fixed in 5:6.0.16-1+deb11u2Fixed in 5:7.0.11-1Fixed in 5:7.0.14-1 - Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 6.2.6 - Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 6.0.16 - Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 5.0.14 - Upgrade
Upgrade
redisto a version that resolves this vulnerability.Fixed in 6.2.6Patch GHSA-9mj9-xx53-qmxm - Upgrade
Upgrade
redisto a version that resolves this vulnerability.Fixed in 6.0.16Patch GHSA-9mj9-xx53-qmxm - Upgrade
Upgrade
redisto a version that resolves this vulnerability.Fixed in 5.0.14Patch GHSA-9mj9-xx53-qmxm
Event History
Frequently Asked Questions
What is CVE-2021-32672?
CVE-2021-32672 is a vulnerability in Redis that allows users to send malformed requests to the Redis Lua Debugger.
How severe is CVE-2021-32672?
CVE-2021-32672 has a severity rating of 4.3, which is considered medium.
What versions of Redis are affected by CVE-2021-32672?
This vulnerability affects all versions of Redis with Lua debugging support (3.2 or newer).
How can I fix CVE-2021-32672?
To fix CVE-2021-32672, you should update Redis to version 6.2.6 or apply the appropriate remediation provided by your operating system or package manager.
Where can I find more information about CVE-2021-32672?
You can find more information about CVE-2021-32672 on the GitHub security advisory page (https://github.com/redis/redis/security/advisories/GHSA-9mj9-xx53-qmxm) or the Redis GitHub repository (https://github.com/redis/redis/commit/6ac3c0b7abd35f37201ed2d6298ecef4ea1ae1dd).