CVE-2026-5759 FalkorDB RDB 解码器双重释放漏洞
影响攻击者可远程造成拒绝服务或执行任意代码
FalkorDB 4.18.1 之前版本的 RDB 图解码器在 RdbLoadDeletedNodes 函数中存在双重释放与释放后使用漏洞。该函数对已删除节点缓冲区长度的校验依赖 ASSERT(),而发布构建中该断言被编译移除,导致长度非 sizeof(NodeID) 整数倍时仍继续处理已释放的缓冲区。攻击者可通过构造恶意 RDB 流触发该缺陷。
影响范围
FalkorDB 4.18.1 之前的版本,涉及 src/serializers/decoders/*/decode_graph_entities.c 中的 RdbLoadDeletedNodes 函数。
漏洞详情
漏洞类型为双重释放(double free)与释放后使用(use-after-free)。成因是删除节点缓冲区长度校验使用 ASSERT(),在 release 构建中被移除,长度非法时函数仍会读取并再次释放同一缓冲区。攻击者通过 Redis 复制命令发送特制 RDB 流,其中已删除节点缓冲区长度不是 sizeof(NodeID) 的整数倍,即可触发内存破坏。
利用条件与风险
利用前提是攻击者能够向目标实例发送 Redis 复制命令,例如实例未配置密码。成功利用可导致 redis-server 进程崩溃(拒绝服务),并可能实现任意代码执行,CVSS 评分 9.8,实战风险极高。
修复建议
官方已在 FalkorDB 4.18.1 中修复,建议升级至该版本或更高版本。临时缓解措施包括为 Redis 实例配置强密码认证、限制复制命令的网络访问来源,避免暴露未授权实例。
A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time.