CVE-2024-51741
MEDIUM4.4EPSS 0.76%Redis allows denial-of-service due to malformed ACL selectors
Published: 1/6/2025Modified: 5/17/2026
Description
Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.
Affected packages (8)
- Alpine/redisfrom 0, < 7.0.15-r2
- Alpine/valkeyfrom 0, < 7.2.8-r0
- Bitnami/keydb>= 7.0.0
- Bitnami/redis>= 7.0.0, < 7.2.8, >= 7.4.0, < 7.4.2
- Bitnami/valkeyfrom 0, < 8.0.2
- Debian/redictfrom 0, < 7.3.2+ds-1
- Debian/redisfrom 0, < 5:7.0.15-1~deb12u3
- Debian/valkeyfrom 0, < 8.0.2+dfsg1-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.4 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
References (7)
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2024-51741
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2024-51741
- WEBhttps://codeberg.org/redict/redict/releases/tag/7.3.2
- WEBhttps://github.com/redis/redis/security/advisories/GHSA-prpq-rh5h-46g9
- WEBhttps://github.com/valkey-io/valkey/releases/tag/8.0.2
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2024-51741
- WEBhttps://redict.io/posts/2025-01-08-redict-7.3.2-released