Corrective releases of the Redis DBMS 7.0.15 and 7.2.4 have fixed a dangerous vulnerability (CVE-2023-41056) that could potentially lead to remote code execution due to data being written outside the allocated buffer area. The issue manifests from the release of Redis 7.0.9 and is caused by incorrect buffer parameter calculations in the sdsResize function when resizing.
Source: opennet.ru