Back to Database
Status published
High
CVE-2023-41056
Redis vulnerable to integer overflow in certain payloads
Vulnerability Description
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-41056
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/redis/redis/security/advisories/GHSA-xr47-pcmx-fq2m
- https://github.com/redis/redis/releases/tag/7.0.15
- https://github.com/redis/redis/releases/tag/7.2.4
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JTGQJ2YLYB24B72I5B5H32YIMPVSWIT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JTWHPLC3RI67VNRDOIXLDVNC5YMYBMQN/
- https://security.netapp.com/advisory/ntap-20240223-0003/
More from redis
View All →CVE-2025-62507
Redis: Bug in XACKDEL may lead to stack overflow and potential RCE
High
7.7
CVE-2025-49844
Redis Lua Use-After-Free may lead to remote code execution
Critical
10
CVE-2025-48367
Redis DoS Vulnerability due to bad connection error handling
High
7.5
CVE-2025-46819
Redis is vulnerable to DoS via specially crafted LUA scripts
Medium
6.3
CVE-2025-46818
Redis: Authenticated users can execute LUA scripts as a different user
Medium
6
Affected Vendor
redis
View all reports →Affected Software
redis
Vulnerable Versions:
>= 7.0.9, < 7.0.15, >= 7.2.0, < 7.2.4
Timeline
Official Publish:
January 10th, 2024
Last Modified:
June 17th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H