漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Malformed Valkey Cluster bus message can lead to Remote DoS
Vulnerability Description
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
跨界内存读
Vulnerability Title
Valkey 缓冲区错误漏洞
Vulnerability Description
Valkey是Valkey开源的一个灵活的分布式键值数据库。 Valkey 9.0.2之前版本、8.1.6之前版本、8.0.7之前版本和7.2.12之前版本存在缓冲区错误漏洞,该漏洞源于集群总线数据包处理代码未验证扩展数据包位置,可能导致越界读取和系统崩溃。
CVSS Information
N/A
Vulnerability Type
N/A