CVE-2022-3647 - CVE House
Back to Database
Status published Low CVE-2022-3647

Redis Crash Report debug.c sigsegvHandler denial of service

Vulnerability Description

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The complexity of an attack is rather high. The exploitability is told to be difficult. The real existence of this vulnerability is still doubted at the moment. Upgrading to version 6.2.8 and 7.0.6 is able to address this issue. The patch is identified as 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability. NOTE: The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3647

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • arkamar (VulDB User)

Affected Vendor

Affected Software

Redis
Vulnerable Versions:
6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5

Timeline

Official Publish: October 21st, 2022
Last Modified: April 15th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)