Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Malformed Valkey Cluster bus message can lead to Remote DoS
Vulnerability Description
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
跨界内存读
Vulnerability Title
Valkey 缓冲区错误漏洞
Vulnerability Description
Valkey是Valkey开源的一个灵活的分布式键值数据库。 Valkey 9.0.2之前版本、8.1.6之前版本、8.0.7之前版本和7.2.12之前版本存在缓冲区错误漏洞,该漏洞源于集群总线数据包处理代码未验证扩展数据包位置,可能导致越界读取和系统崩溃。
CVSS Information
N/A
Vulnerability Type
N/A