Bug 2137209 (CVE-2022-3647)

Summary: CVE-2022-3647 redis: crash in sigsegvHandler debug function
Product: [Other] Security Response Reporter: Borja Tarraso <btarraso>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: adudiak, aileenc, amackenz, amasferr, bdettelb, chazlett, cmeyers, dhalasz, eglynn, gblomqui, gmalinko, gparvin, hhorak, janstey, jjoyce, jochrist, jorton, jwong, jwon, kaycoth, kshier, lhh, mabashia, mburns, mgarciac, micjohns, mkudlej, nathans, njean, notting, owatkins, pahickey, pdelbell, rcollet, redis-maint, rpetrell, smcdonal, spower, stcannon, sthirugn, teagle, tfister, tjochec, vkrizan, vmugicag
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Redis when calling the sigsegvHandler function of the debug component crash report. This issue causes a crash, ignoring the report information and kills the processes, which leads to a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2143619, 2137210, 2137211, 2137212, 2137213, 2137340, 2137341    
Bug Blocks: 2137112    

Description Borja Tarraso 2022-10-24 07:45:45 UTC
A vulnerability, which was classified as problematic, was found in Redis. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The name of the patch is 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability.

Comment 1 Borja Tarraso 2022-10-24 07:46:18 UTC
Created redis tracking bugs for this issue:

Affects: epel-7 [bug 2137210]
Affects: fedora-all [bug 2137211]