Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://github.com/redis/redis/commit/4a7a4e42db8ff757cdf3f4a824f66426036034ef | third party advisory patch |
https://github.com/redis/redis/pull/10753 | issue tracking patch exploit third party advisory |
https://raw.githubusercontent.com/redis/redis/7.0.1/00-RELEASENOTES | third party advisory release notes |
https://github.com/redis/redis/pull/10829 | issue tracking release notes exploit third party advisory |
https://security.netapp.com/advisory/ntap-20220729-0005/ | third party advisory |
https://security.gentoo.org/glsa/202209-17 | third party advisory vendor advisory |