Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue affects Apache Kvrocks: through 2.11.1. Users are recommended to upgrade to version 2.12.0, which fixes the issue.
History

Tue, 22 Apr 2025 09:45:00 +0000

Type Values Removed Values Added
References

Tue, 22 Apr 2025 07:30:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue affects Apache Kvrocks: through 2.11.1. Users are recommended to upgrade to version 2.12.0, which fixes the issue.
Title Apache Kvrocks: The server was crashed by the negative offset
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-04-22T07:07:49.985Z

Updated: 2025-04-22T10:57:37.160Z

Reserved: 2025-02-10T12:29:42.521Z

Link: CVE-2025-26413

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-22T08:15:28.853

Modified: 2025-04-23T14:08:13.383

Link: CVE-2025-26413

cve-icon Redhat

No data.