We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-26413

Apache Kvrocks: The server was crashed by the negative offset



Description

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue affects Apache Kvrocks: through 2.11.1. Users are recommended to upgrade to version 2.12.0, which fixes the issue.

Reserved 2025-02-10 | Published 2025-04-22 | Updated 2025-05-12 | Assigner apache

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version
affected

Credits

ankki-zsyang, Shenzhen Ankki Technologies Co., Ltd. reporter

References

lists.apache.org/thread/388743qrr8yq8qm0go8tls6rf1kog8dw vendor-advisory

cve.org (CVE-2025-26413)

nvd.nist.gov (CVE-2025-26413)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-26413

Support options

Helpdesk Chat, Email, Knowledgebase