redis: integer overflow in the getnum function in lua_struct.c could lead to a DoS (CVE-2020-14147)
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression.
References:
- https://nvd.nist.gov/vuln/detail/CVE-2020-14147
- Issue re-introduced with https://github.com/antirez/redis/commit/1eb08bcd4634ae42ec45e8284923ac048beaa4c3 (5.0-rc4)
Patch:
https://github.com/antirez/redis/commit/ef764dde1cca2f25d00686673d1bc89448819571
Affected branches:
-
master (e46a3ccc) -
3.12-stable -
3.11-stable -
3.10-stable