Skip to content

[Security] CVE-2023-28856: HINCRBYFLOAT produces invalid ziplist values #960

Description

@vulgraph

Vulnerability

KeyDB inherits CVE-2023-28856 from Redis — HINCRBYFLOAT accepts extreme floating-point values that produce invalid data in ziplist encoding.

Reproduction

keydb-cli HSET h f 1e308
keydb-cli HINCRBYFLOAT h f 1e308

Produces a 309-digit number stored in ziplist, which can trigger assertion failures on subsequent operations.

Tested Version

KeyDB latest master (git sha 603ebb27).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions