{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/rick2600/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["rick2600"],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2024-55656"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RedisBloom (\u003c 2.6.12)","Redis Stack (7.2.0-v10)","Redis (\u003c 6.2.17)","Redis (7.2.7)","Redis (7.4.2)"],"_cs_severities":["high"],"_cs_tags":["redis","cve","rce","memory-corruption"],"_cs_type":"threat","_cs_vendors":["Redis"],"content_html":"\u003cp\u003eCVE-2024-55656 is an integer overflow vulnerability affecting the RedisBloom module, specifically versions including v2.6.12 as found in Redis Stack 7.2.0-v10. The vulnerability resides in the CMS.INITBYDIM command, which initializes a Count-Min Sketch. By providing manipulated width and depth parameters, an attacker can cause an integer overflow during memory calculation, resulting in a heap buffer underallocation. Because the system allocates less memory than required, subsequent calls to CMS.QUERY (for out-of-bounds reading) or CMS.INCRBY (for out-of-bounds writing) allow for memory corruption, potential information disclosure, and ultimately, arbitrary code execution. This vulnerability requires the attacker to be authenticated to the Redis instance. Defenders should prioritize patching RedisBloom modules and monitoring for abnormal parameter values passed to CMS-related commands.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes an authenticated session with a target Redis instance.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a Redis server running a vulnerable version of the RedisBloom module.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious CMS.INITBYDIM command with extreme width and depth parameters.\u003c/li\u003e\n\u003cli\u003eThe module's NewCMSketch function performs an insecure multiplication of these parameters, leading to an integer overflow.\u003c/li\u003e\n\u003cli\u003eThe heap allocation routine allocates a buffer smaller than the expected size based on the overflowed integer.\u003c/li\u003e\n\u003cli\u003eAttacker sends a CMS.INCRBY command targeting indices that fall outside the allocated heap memory.\u003c/li\u003e\n\u003cli\u003eThe out-of-bounds write corrupts heap metadata or surrounding data structures to control execution flow.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution within the context of the Redis process.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a remote, authenticated attacker to achieve arbitrary code execution on the server hosting the Redis instance. This impact covers critical confidentiality, integrity, and availability (CVSS 8.8-9.8). The vulnerability affects deployments of Redis Stack and RedisBloom, potentially exposing infrastructure components relying on Redis for caching or data processing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch all Redis and RedisBloom instances to the secure versions listed in the vendor advisory: Redis \u0026lt; 6.2.17, 7.2.7, and 7.4.2.\u003c/li\u003e\n\u003cli\u003eAudit Redis access controls to ensure that only authorized clients possess the credentials required to interact with the service.\u003c/li\u003e\n\u003cli\u003eImplement network-level segmentation to restrict access to the Redis port (default 6379) to known, trusted application servers only.\u003c/li\u003e\n\u003cli\u003eReview Redis logs for abnormally large integer values used as arguments in CMS.INITBYDIM or related CMS commands, as these may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-03T17:01:06Z","date_published":"2026-10-03T17:01:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-redis-bloom-integer-overflow/","summary":"An integer overflow vulnerability (CVE-2024-55656) in the RedisBloom module's CMS.INITBYDIM command enables heap underallocation, allowing authenticated attackers to perform out-of-bounds memory operations and achieve remote code execution.","title":"Remote Code Execution via Integer Overflow in RedisBloom Module","url":"https://feed.craftedsignal.io/briefs/2026-10-redis-bloom-integer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Rick2600","version":"https://jsonfeed.org/version/1.1"}