{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "contain a segmentation violation in redisraft.c",
    "tracking": {
      "current_release_date": "2026-08-11T16:54:28+00:00",
      "generator": {
        "date": "2026-08-11T16:54:28+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2023-31655",
      "initial_release_date": "2023-05-18T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T16:54:28+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat OpenStack Platform rhos-13.0.z",
            "product": {
              "name": "Red Hat OpenStack Platform rhos-13.0.z",
              "product_id": "openstack-13",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openstack:13"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.10.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.10.z",
              "product_id": "rhel-8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 9.9",
            "product": {
              "name": "Red Hat Enterprise Linux 9.9",
              "product_id": "rhel-9",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:9"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Software Collections",
            "product": {
              "name": "Red Hat Software Collections",
              "product_id": "rhscl-3",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhel_software_collections:3"
              }
            }
          },
          {
            "category": "product_version",
            "name": "redis",
            "product": {
              "name": "redis",
              "product_id": "redis",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/redis"
              }
            }
          },
          {
            "category": "product_version",
            "name": "redis-devel",
            "product": {
              "name": "redis-devel",
              "product_id": "redis-devel",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/redis-devel"
              }
            }
          },
          {
            "category": "product_version",
            "name": "redis-doc",
            "product": {
              "name": "redis-doc",
              "product_id": "redis-doc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/redis-doc"
              }
            }
          },
          {
            "category": "product_version",
            "name": "redis",
            "product": {
              "name": "redis",
              "product_id": "redis.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/redis?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "redis:6/redis",
            "product": {
              "name": "redis:6/redis",
              "product_id": "redis:6/redis.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/redis?arch=src&rpmmod=redis:6"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rh-redis6-redis",
            "product": {
              "name": "rh-redis6-redis",
              "product_id": "rh-redis6-redis",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rh-redis6-redis"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rh-redis6-redis",
            "product": {
              "name": "rh-redis6-redis",
              "product_id": "rh-redis6-redis.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rh-redis6-redis?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:redis"
        },
        "product_reference": "redis",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:redis"
        },
        "product_reference": "redis",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis as a component of Red Hat OpenStack Platform rhos-13.0.z",
          "product_id": "openstack-13:redis"
        },
        "product_reference": "redis",
        "relates_to_product_reference": "openstack-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-devel as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:redis-devel"
        },
        "product_reference": "redis-devel",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-devel as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:redis-devel"
        },
        "product_reference": "redis-devel",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-doc as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:redis-doc"
        },
        "product_reference": "redis-doc",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis-doc as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:redis-doc"
        },
        "product_reference": "redis-doc",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis.src as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:redis.src"
        },
        "product_reference": "redis.src",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis.src as a component of Red Hat OpenStack Platform rhos-13.0.z",
          "product_id": "openstack-13:redis.src"
        },
        "product_reference": "redis.src",
        "relates_to_product_reference": "openstack-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "redis:6/redis.src as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:redis:6/redis.src"
        },
        "product_reference": "redis:6/redis.src",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-redis6-redis as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:rh-redis6-redis"
        },
        "product_reference": "rh-redis6-redis",
        "relates_to_product_reference": "rhscl-3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-redis6-redis.src as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:rh-redis6-redis.src"
        },
        "product_reference": "rh-redis6-redis.src",
        "relates_to_product_reference": "rhscl-3"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-31655",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "discovery_date": "2023-05-19T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-8:redis-devel",
            "rhel-8:redis-doc",
            "rhel-9:redis-devel",
            "rhel-9:redis-doc"
          ]
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability was found in the Redis package. This security flaw causes a segmentation violation in redisraft.c.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "openstack-13:redis",
          "openstack-13:redis.src",
          "rhel-8:redis",
          "rhel-8:redis:6/redis.src",
          "rhel-9:redis",
          "rhel-9:redis.src",
          "rhscl-3:rh-redis6-redis",
          "rhscl-3:rh-redis6-redis.src"
        ],
        "known_not_affected": [
          "rhel-8:redis-devel",
          "rhel-8:redis-doc",
          "rhel-9:redis-devel",
          "rhel-9:redis-doc"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2023-31655"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31655"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-31655"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Out of support scope",
          "product_ids": [
            "openstack-13:redis",
            "openstack-13:redis.src"
          ]
        },
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhel-8:redis",
            "rhel-8:redis:6/redis.src",
            "rhel-9:redis",
            "rhel-9:redis.src",
            "rhscl-3:rh-redis6-redis",
            "rhscl-3:rh-redis6-redis.src"
          ]
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "openstack-13:redis",
            "openstack-13:redis.src",
            "rhel-8:redis",
            "rhel-8:redis:6/redis.src",
            "rhel-9:redis",
            "rhel-9:redis.src",
            "rhscl-3:rh-redis6-redis",
            "rhscl-3:rh-redis6-redis.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH"
          },
          "products": [
            "openstack-13:redis",
            "openstack-13:redis.src",
            "rhel-8:redis",
            "rhel-8:redis-devel",
            "rhel-8:redis-doc",
            "rhel-8:redis:6/redis.src",
            "rhel-9:redis",
            "rhel-9:redis-devel",
            "rhel-9:redis-doc",
            "rhel-9:redis.src",
            "rhscl-3:rh-redis6-redis",
            "rhscl-3:rh-redis6-redis.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "openstack-13:redis",
            "openstack-13:redis.src",
            "rhel-8:redis",
            "rhel-8:redis-devel",
            "rhel-8:redis-doc",
            "rhel-8:redis:6/redis.src",
            "rhel-9:redis",
            "rhel-9:redis-devel",
            "rhel-9:redis-doc",
            "rhel-9:redis.src",
            "rhscl-3:rh-redis6-redis",
            "rhscl-3:rh-redis6-redis.src"
          ]
        }
      ],
      "title": "contain a segmentation violation in redisraft.c"
    }
  ]
}