ALAS-2024-538


Amazon Linux 2023 Security Advisory: ALAS-2024-538
Advisory Release Date: 2024-02-15 03:00 Pacific
Advisory Updated Date: 2024-02-19 20:26 Pacific
Severity: Important

Issue Overview:

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4. (CVE-2023-41056)


Affected Packages:

redis6


Issue Correction:
Run dnf update redis6 --releasever 2023.3.20240219 to update your system.

New Packages:
aarch64:
    redis6-debuginfo-6.2.14-1.amzn2023.0.1.aarch64
    redis6-devel-6.2.14-1.amzn2023.0.1.aarch64
    redis6-6.2.14-1.amzn2023.0.1.aarch64
    redis6-debugsource-6.2.14-1.amzn2023.0.1.aarch64

noarch:
    redis6-doc-6.2.14-1.amzn2023.0.1.noarch

src:
    redis6-6.2.14-1.amzn2023.0.1.src

x86_64:
    redis6-devel-6.2.14-1.amzn2023.0.1.x86_64
    redis6-debuginfo-6.2.14-1.amzn2023.0.1.x86_64
    redis6-6.2.14-1.amzn2023.0.1.x86_64
    redis6-debugsource-6.2.14-1.amzn2023.0.1.x86_64