Vulnerability record · CVE-2016-8339 · published 28 October 2016
CVE-2016-8339: Redislabs redis out-of-bounds write vulnerability
Redislabs · Redis
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.
Description
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/93283 | Third Party AdvisoryVDB Entry |
| http://www.talosintelligence.com/reports/TALOS-2016-0206/ | ExploitThird Party Advisory |
| https://github.com/antirez/redis/commit/6d9f8e2462fc2c426d48c941edeb78e5df7d2977 | PatchThird Party Advisory |
| https://security.gentoo.org/glsa/201702-16 | Third Party Advisory |
| http://www.securityfocus.com/bid/93283 | Third Party AdvisoryVDB Entry |
| http://www.talosintelligence.com/reports/TALOS-2016-0206/ | ExploitThird Party Advisory |
| https://github.com/antirez/redis/commit/6d9f8e2462fc2c426d48c941edeb78e5df7d2977 | PatchThird Party Advisory |
| https://security.gentoo.org/glsa/201702-16 | Third Party Advisory |
Track CVE-2016-8339 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-8339), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.