<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Rick2600 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/rick2600/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 17:01:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/rick2600/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution via Integer Overflow in RedisBloom Module</title><link>https://feed.craftedsignal.io/briefs/2026-10-redis-bloom-integer-overflow/</link><pubDate>Sat, 03 Oct 2026 17:01:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-redis-bloom-integer-overflow/</guid><description>An integer overflow vulnerability (CVE-2024-55656) in the RedisBloom module's CMS.INITBYDIM command enables heap underallocation, allowing authenticated attackers to perform out-of-bounds memory operations and achieve remote code execution.</description><content:encoded><![CDATA[<p>CVE-2024-55656 is an integer overflow vulnerability affecting the RedisBloom module, specifically versions including v2.6.12 as found in Redis Stack 7.2.0-v10. The vulnerability resides in the CMS.INITBYDIM command, which initializes a Count-Min Sketch. By providing manipulated width and depth parameters, an attacker can cause an integer overflow during memory calculation, resulting in a heap buffer underallocation. Because the system allocates less memory than required, subsequent calls to CMS.QUERY (for out-of-bounds reading) or CMS.INCRBY (for out-of-bounds writing) allow for memory corruption, potential information disclosure, and ultimately, arbitrary code execution. This vulnerability requires the attacker to be authenticated to the Redis instance. Defenders should prioritize patching RedisBloom modules and monitoring for abnormal parameter values passed to CMS-related commands.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker establishes an authenticated session with a target Redis instance.</li>
<li>Attacker identifies a Redis server running a vulnerable version of the RedisBloom module.</li>
<li>Attacker constructs a malicious CMS.INITBYDIM command with extreme width and depth parameters.</li>
<li>The module's NewCMSketch function performs an insecure multiplication of these parameters, leading to an integer overflow.</li>
<li>The heap allocation routine allocates a buffer smaller than the expected size based on the overflowed integer.</li>
<li>Attacker sends a CMS.INCRBY command targeting indices that fall outside the allocated heap memory.</li>
<li>The out-of-bounds write corrupts heap metadata or surrounding data structures to control execution flow.</li>
<li>Attacker achieves remote code execution within the context of the Redis process.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a remote, authenticated attacker to achieve arbitrary code execution on the server hosting the Redis instance. This impact covers critical confidentiality, integrity, and availability (CVSS 8.8-9.8). The vulnerability affects deployments of Redis Stack and RedisBloom, potentially exposing infrastructure components relying on Redis for caching or data processing.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch all Redis and RedisBloom instances to the secure versions listed in the vendor advisory: Redis &lt; 6.2.17, 7.2.7, and 7.4.2.</li>
<li>Audit Redis access controls to ensure that only authorized clients possess the credentials required to interact with the service.</li>
<li>Implement network-level segmentation to restrict access to the Redis port (default 6379) to known, trusted application servers only.</li>
<li>Review Redis logs for abnormally large integer values used as arguments in CMS.INITBYDIM or related CMS commands, as these may indicate exploitation attempts.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>redis</category><category>cve</category><category>rce</category><category>memory-corruption</category></item></channel></rss>