Impact
The flaw is a double free followed by a use‑after‑free in FalkorDB’s RdbLoadDeletedNodes Graph decoder. A malicious RDB stream whose deleted‑nodes buffer length is not a multiple of the NodeID size bypasses a length check that relies on an assert removed from release builds. The function therefore frees the buffer, continues to read it, and frees it again, allowing a remote attacker to trigger a denial of service or execute arbitrary code within the redis-server process.
Affected Systems
Affected software is FalkorDB, any deployment running a version prior to 4.18.1. The vulnerability is tied to the graph decoding logic in that product and is not limited to a particular platform. The provided CPE indicates all variants of FalkorDB are impacted, and the advisory advises upgrading to 4.18.1 or later.
Risk and Exploitability
The CVSS score is 9.3, indicating a critical severity. No EPSS score is available, but the vulnerability is not listed in CISA’s KEV catalog. The exploit requires an attacker who can issue Redis replication commands against an unprotected instance, so the attack vector is remote over the network to an unauthenticated service. Because the flaw resides in core decoding code that runs during normal replication, a successful exploit would allow control of the server process if an attacker can supply a crafted RDB payload, making the risk high for exposed or insecure instances.
OpenCVE Enrichment