Advisories ยป MGASA-2023-0156

Updated redis packages fix security vulnerability

Publication date: 24 Apr 2023
Modification date: 23 Apr 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2023-28856

Description

Authenticated users can use the HINCRBYFLOAT command to create an invalid
hash field that will crash Redis on access. (CVE-2023-28856)
                

References

SRPMS

8/core