REDHAT-BUG-2174306: Medium severity ioredis vulnerability
(CVE-2022-36021) String matching commands (like SCAN or KEYS) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. https://github.com/gentoo/gentoo/pull/29860
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2174306?
REDHAT-BUG-2174306 is a critical vulnerability affecting Redis that can lead to a denial-of-service attack.
How do I fix REDHAT-BUG-2174306?
To fix REDHAT-BUG-2174306, you should update your Redis installation to the latest version that addresses this vulnerability.
What are the impacts of REDHAT-BUG-2174306?
The impact of REDHAT-BUG-2174306 includes causing Redis to hang and consume 100% CPU time, disrupting service availability.
Which Redis versions are affected by REDHAT-BUG-2174306?
All versions of Redis prior to the fix for REDHAT-BUG-2174306 are potentially affected.
Is there a workaround for REDHAT-BUG-2174306?
A temporary workaround for REDHAT-BUG-2174306 is to avoid using string matching commands with crafted patterns.