RHSA-2021:2034: Important: redis:6 security update
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log.Security Fix(es): redis: Integer overflow via STRALGO LCS command (CVE-2021-29477) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 6.0.9-3.module+el8.4.0+10984+ed187465 - Upgrade
Upgrade
redhat/redis-docto a version that resolves this vulnerability.Fixed in 6.0.9-3.module+el8.4.0+10984+ed187465 - Upgrade
Upgrade
redhat/redis-debuginfoto a version that resolves this vulnerability.Fixed in 6.0.9-3.module+el8.4.0+10984+ed187465 - Upgrade
Upgrade
redhat/redis-debugsourceto a version that resolves this vulnerability.Fixed in 6.0.9-3.module+el8.4.0+10984+ed187465 - Upgrade
Upgrade
redhat/redis-develto a version that resolves this vulnerability.Fixed in 6.0.9-3.module+el8.4.0+10984+ed187465 - Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 6.0.9-3.module+el8.4.0+10984+ed187465.aa - Upgrade
Upgrade
redhat/redis-debuginfoto a version that resolves this vulnerability.Fixed in 6.0.9-3.module+el8.4.0+10984+ed187465.aa - Upgrade
Upgrade
redhat/redis-debugsourceto a version that resolves this vulnerability.Fixed in 6.0.9-3.module+el8.4.0+10984+ed187465.aa - Upgrade
Upgrade
redhat/redis-develto a version that resolves this vulnerability.Fixed in 6.0.9-3.module+el8.4.0+10984+ed187465.aa - Upgrade
Upgrade
redisto a version that resolves this vulnerability.Fixed in 6 - Compensating control
If you cannot upgrade immediately, mitigate the CVE-2021-29477 integer overflow reachable via the Redis STRALGO LCS command (CVE-2021-29477).
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2034?
RHSA-2021:2034 has a severity rating that indicates it is critical due to vulnerabilities that could lead to data exposure or integrity issues.
How do I fix RHSA-2021:2034?
To resolve RHSA-2021:2034, upgrade your Redis packages to version 6.0.9-3.module+el8.4.0+10984+ed187465.
Which software is affected by RHSA-2021:2034?
RHSA-2021:2034 affects multiple Redis packages including redis, redis-doc, redis-devel, and their debug versions.
What impact might RHSA-2021:2034 have on my system?
If left unpatched, RHSA-2021:2034 could allow an attacker to exploit vulnerabilities, potentially leading to unauthorized access to Redis data.
Is there a workaround for RHSA-2021:2034?
There are no specific workarounds for RHSA-2021:2034; the recommended action is to apply the available updates immediately.