Valkey 是一个分布式键值数据库。在版本 7.2.14、8.0.10、8.1.9、9.0.5 和 9.1.1 之前,Valkey 的 函数在遍历 时,经过身份验证的客户端可以触发 命令,导致 删除迭代器缓存的下一个节点,从而引发使用-after-free(use-after-free)漏洞。当启用 TLS 时,该漏洞可能导致服务器崩溃,甚至可能被利用以实现远程代码执行。此问题已在版本 7.2.14、8.0.10、8.1.9、9.0.5 和 9.1.1 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet