Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Debian DSA-6279-1 Redis Important CVE-2025-67733 DoS Risk

debian
Calendar Grey May 17, 2026
Debian Logo
A denial of service and injection risk in redis affects Debian users, requiring immediate updates for security.
Brief introduction CVE-2025-67733 A flaw in the Lua scripting error path allowed an authenticated user to embed CR/LF byte sequences in an error reply produced via redis.error_repl...

Summary

CVE-2025-67733

A flaw in the Lua scripting error path allowed an authenticated user
to embed CR/LF byte sequences in an error reply produced via
redis.error_reply() or the Lua error() function. Because RESP uses
CRLF as a frame delimiter, an injected sequence could be interpreted
by the client as the start of an unrelated reply, allowing an
attacker to inject arbitrary content into the response stream and
tamper with data read by other commands on the same connection.

CVE-2026-21863

The cluster bus packet validation in clusterProcessPacket() did not
verify that the gossip-section count and per-extension header
declared by an incoming PING, PONG or MEET message actually fit
within the received packet. A peer with access to the cluster bus
port could send a specially crafted message whose declared lengths
exceed the packet size, causing the server to read out of bounds and
potentially crash, resulting in a denial of service.

For the oldstable di...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: redis
CVE ID: CVE-2025-67733 CVE-2026-21863

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here