Impact
The FalkorDB Redis module contains a stack overflow in the _ValidateUnion_Clauses function, which can be triggered by a specially crafted input. When exploited, the overflow corrupts stack data and can cause the module to crash, leading to a denial of service for the Redis instance. This weakness is a buffer overrun that compromises the integrity and availability of the database system, but does not expose sensitive data or create code execution possibilities.
Affected Systems
The affected product is FalkorDB, a Redis module, for all releases from version 4.20.1 through 4.20.4. No other vendor or product variants are noted in the advisory.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and although the EPSS score is not available, the absence of a KEV listing does not reduce its potential impact. The flaw is exploitable through the module’s command interface; an attacker with ability to send commands to Redis, whether remotely or locally, can construct the payload that overflows the stack and forces a crash. Because the module is compiled into the Redis process, a successful exploitation results in a service denial without the need for further privilege escalation.
OpenCVE Enrichment