{
  "document": {
    "aggregate_severity": {
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/vex/2022/cve-2022-3647-els_os-debian10els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-09T17:29:54Z",
      "generator": {
        "date": "2026-07-09T17:29:54Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2022-3647-ELS_OS-DEBIAN10ELS",
      "initial_release_date": "2022-10-21T18:15:00Z",
      "revision_history": [
        {
          "date": "2022-10-21T18:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-09T17:29:54Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2022-3647"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "redis-5:5.0.14-1+deb10u5.all",
                "product": {
                  "name": "redis-5:5.0.14-1+deb10u5.all",
                  "product_id": "redis-5:5.0.14-1+deb10u5.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/redis@5:5.0.14-1%2Bdeb10u5?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "redis-server-5:5.0.14-1+deb10u5.amd64",
                "product": {
                  "name": "redis-server-5:5.0.14-1+deb10u5.amd64",
                  "product_id": "redis-server-5:5.0.14-1+deb10u5.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/redis-server@5:5.0.14-1%2Bdeb10u5?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "redis-tools-5:5.0.14-1+deb10u5.amd64",
                "product": {
                  "name": "redis-tools-5:5.0.14-1+deb10u5.amd64",
                  "product_id": "redis-tools-5:5.0.14-1+deb10u5.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/redis-tools@5:5.0.14-1%2Bdeb10u5?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "redis-sentinel-5:5.0.14-1+deb10u5.amd64",
                "product": {
                  "name": "redis-sentinel-5:5.0.14-1+deb10u5.amd64",
                  "product_id": "redis-sentinel-5:5.0.14-1+deb10u5.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/redis-sentinel@5:5.0.14-1%2Bdeb10u5?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "redis-5:5.0.14-1+deb10u5+tuxcare.els3.all",
                "product": {
                  "name": "redis-5:5.0.14-1+deb10u5+tuxcare.els3.all",
                  "product_id": "redis-5:5.0.14-1+deb10u5+tuxcare.els3.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/redis@5:5.0.14-1%2Bdeb10u5%2Btuxcare.els3?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "redis-5:5.0.14-1+deb10u5+tuxcare.els2.all",
                "product": {
                  "name": "redis-5:5.0.14-1+deb10u5+tuxcare.els2.all",
                  "product_id": "redis-5:5.0.14-1+deb10u5+tuxcare.els2.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/redis@5:5.0.14-1%2Bdeb10u5%2Btuxcare.els2?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
                "product": {
                  "name": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
                  "product_id": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/redis-server@5:5.0.14-1%2Bdeb10u5%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
                "product": {
                  "name": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
                  "product_id": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/redis-server@5:5.0.14-1%2Bdeb10u5%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
                "product": {
                  "name": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
                  "product_id": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/redis-tools@5:5.0.14-1%2Bdeb10u5%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
                "product": {
                  "name": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
                  "product_id": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/redis-tools@5:5.0.14-1%2Bdeb10u5%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
                "product": {
                  "name": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
                  "product_id": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/redis-sentinel@5:5.0.14-1%2Bdeb10u5%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
                "product": {
                  "name": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
                  "product_id": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/redis-sentinel@5:5.0.14-1%2Bdeb10u5%2Btuxcare.els2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-5:5.0.14-1+deb10u5+tuxcare.els3.all as a component of Debian 10",
          "product_id": "Debian-10:redis-5:5.0.14-1+deb10u5+tuxcare.els3.all"
        },
        "product_reference": "redis-5:5.0.14-1+deb10u5+tuxcare.els3.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-5:5.0.14-1+deb10u5.all as a component of Debian 10",
          "product_id": "Debian-10:redis-5:5.0.14-1+deb10u5.all"
        },
        "product_reference": "redis-5:5.0.14-1+deb10u5.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-5:5.0.14-1+deb10u5+tuxcare.els2.all as a component of Debian 10",
          "product_id": "Debian-10:redis-5:5.0.14-1+deb10u5+tuxcare.els2.all"
        },
        "product_reference": "redis-5:5.0.14-1+deb10u5+tuxcare.els2.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:redis-server-5:5.0.14-1+deb10u5+tuxcare.els2.amd64"
        },
        "product_reference": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-server-5:5.0.14-1+deb10u5.amd64 as a component of Debian 10",
          "product_id": "Debian-10:redis-server-5:5.0.14-1+deb10u5.amd64"
        },
        "product_reference": "redis-server-5:5.0.14-1+deb10u5.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els3.amd64 as a component of Debian 10",
          "product_id": "Debian-10:redis-server-5:5.0.14-1+deb10u5+tuxcare.els3.amd64"
        },
        "product_reference": "redis-server-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els3.amd64 as a component of Debian 10",
          "product_id": "Debian-10:redis-tools-5:5.0.14-1+deb10u5+tuxcare.els3.amd64"
        },
        "product_reference": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-tools-5:5.0.14-1+deb10u5.amd64 as a component of Debian 10",
          "product_id": "Debian-10:redis-tools-5:5.0.14-1+deb10u5.amd64"
        },
        "product_reference": "redis-tools-5:5.0.14-1+deb10u5.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:redis-tools-5:5.0.14-1+deb10u5+tuxcare.els2.amd64"
        },
        "product_reference": "redis-tools-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els3.amd64 as a component of Debian 10",
          "product_id": "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els3.amd64"
        },
        "product_reference": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-sentinel-5:5.0.14-1+deb10u5.amd64 as a component of Debian 10",
          "product_id": "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5.amd64"
        },
        "product_reference": "redis-sentinel-5:5.0.14-1+deb10u5.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els2.amd64"
        },
        "product_reference": "redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2022-3647",
      "cwe": {
        "id": "CWE-404",
        "name": "Improper Resource Shutdown or Release"
      },
      "notes": [
        {
          "category": "description",
          "text": "** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The complexity of an attack is rather high. The exploitability is told to be difficult. The real existence of this vulnerability is still doubted at the moment. Upgrading to version 6.2.8 and 7.0.6 is able to address this issue. The patch is identified as 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability. NOTE: The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-10:redis-5:5.0.14-1+deb10u5+tuxcare.els2.all",
          "Debian-10:redis-5:5.0.14-1+deb10u5+tuxcare.els3.all",
          "Debian-10:redis-5:5.0.14-1+deb10u5.all",
          "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
          "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
          "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5.amd64",
          "Debian-10:redis-server-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
          "Debian-10:redis-server-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
          "Debian-10:redis-server-5:5.0.14-1+deb10u5.amd64",
          "Debian-10:redis-tools-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
          "Debian-10:redis-tools-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
          "Debian-10:redis-tools-5:5.0.14-1+deb10u5.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2022-3647"
        },
        {
          "category": "external",
          "summary": "https://github.com/redis/redis/commit/0bf90d944313919eb8e63d3588bf63a367f020a3",
          "url": "https://github.com/redis/redis/commit/0bf90d944313919eb8e63d3588bf63a367f020a3"
        },
        {
          "category": "external",
          "summary": "https://vuldb.com/?ctiid.211962",
          "url": "https://vuldb.com/?ctiid.211962"
        },
        {
          "category": "external",
          "summary": "https://vuldb.com/?id.211962",
          "url": "https://vuldb.com/?id.211962"
        }
      ],
      "release_date": "2022-10-21T18:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-09T16:57:24.584860Z",
          "details": "CVE-2022-3647 concerns Redis’s sigsegvHandler crash-reporting routine, which only executes after the process has already crashed; the vendor disputes it as a DoS because it does not introduce a new crash condition nor affect confidentiality or integrity. The CVSS reflects a local-only vector with low privileges, offering no practical remote exploit path in typical server/VM deployments. At worst it marginally impacts availability during an already-failing event, so it can be safely deprioritized.",
          "product_ids": [
            "Debian-10:redis-5:5.0.14-1+deb10u5+tuxcare.els2.all",
            "Debian-10:redis-5:5.0.14-1+deb10u5+tuxcare.els3.all",
            "Debian-10:redis-5:5.0.14-1+deb10u5.all",
            "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
            "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
            "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5.amd64",
            "Debian-10:redis-server-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
            "Debian-10:redis-server-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
            "Debian-10:redis-server-5:5.0.14-1+deb10u5.amd64",
            "Debian-10:redis-tools-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
            "Debian-10:redis-tools-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
            "Debian-10:redis-tools-5:5.0.14-1+deb10u5.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 3.3,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Debian-10:redis-5:5.0.14-1+deb10u5+tuxcare.els2.all",
            "Debian-10:redis-5:5.0.14-1+deb10u5+tuxcare.els3.all",
            "Debian-10:redis-5:5.0.14-1+deb10u5.all",
            "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
            "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
            "Debian-10:redis-sentinel-5:5.0.14-1+deb10u5.amd64",
            "Debian-10:redis-server-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
            "Debian-10:redis-server-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
            "Debian-10:redis-server-5:5.0.14-1+deb10u5.amd64",
            "Debian-10:redis-tools-5:5.0.14-1+deb10u5+tuxcare.els2.amd64",
            "Debian-10:redis-tools-5:5.0.14-1+deb10u5+tuxcare.els3.amd64",
            "Debian-10:redis-tools-5:5.0.14-1+deb10u5.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    }
  ]
}