Impact
A heap-based out-of-bounds read in FalkorDB’s BufferSerializerIOv2_ReadBuffer function allows an attacker to cause the server to read beyond the bounds of a heap allocation. When a crafted RDB stream with a sub-buffer length larger than the remaining buffer size is supplied over the replication interface, memcpy() pulls data past the end of the allocated block, which can lead to either a server crash or leakage of arbitrary heap contents. This vulnerability is identified as a CWE‑125 error.
Affected Systems
FalkorDB (any release prior to version 4.18.4) is impacted. The flaw exists in the replication component and applies to all instances running the vulnerable code without a safe‑guarded replication path.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, and its EPSS score is not available at the time of this analysis. It has not yet entered CISA’s KEV catalog. Exploitation requires remote access to the replication channel, which is normally permitted in unauthenticated instances. An attacker who can issue replication commands – such as REPLICAOF/SLAVEOF – can download a malicious RDB stream and trigger the heap read. The attack can be carried out without additional privileges if the instance is exposed to untrusted networks. Given its high severity and the realistic exploitation path, the risk is substantial for exposed systems.
OpenCVE Enrichment