Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in FalkorDB's RDB graph decoders could allow an attacker to cause a denial of service or execute arbitrary code. This is due to how the system handles deleted nodes, where a length check can be bypassed in release builds, leading to a double-free and use-after-free condition. The main concern is confirming relevance and exposure.
- Double free vulnerability in database decoding.
- Affects data integrity and server process availability.
- Confirm if FalkorDB is in use and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending a specially crafted RDB stream to a FalkorDB instance that is not password-protected and uses Redis replication. This crafted stream targets the RDB graph decoders, specifically the `RdbLoadDeletedNodes` function. By providing a deleted-nodes buffer length that is not a multiple of the expected size, the attacker can trigger a double free and use-after-free condition. This faulty memory handling, which bypasses release build assertions, can lead to a denial of service or allow for arbitrary code execution within the FalkorDB server process.
- Entry condition: Network access to an unprotected FalkorDB instance.
- Trigger point: Supplying a crafted RDB stream.
- Resulting risk: Denial of service or code execution.
Live Threat
Current exploitation, exposure, and threat context
A remote attacker could trigger a double free and use-after-free vulnerability in FalkorDB's RDB graph decoders. This may allow for denial of service or arbitrary code execution within the redis-server process when a crafted RDB stream is provided.
- Server process memory and execution.
- Via crafted RDB stream over replication.
- Denial of service or code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The FalkorDB database administrators and infrastructure teams are responsible for addressing this vulnerability. The initial step is to locate all instances of FalkorDB, determine their exposure and criticality, and identify the designated owner for each instance. Subsequently, a remediation plan should be developed based on the identified risks.
- Identify FalkorDB deployments and owners.
- Verify instance reachability and criticality.
- Plan remediation based on risk.