Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 11: DLA-4240-1 important: redis DoS and remote code execution

debian lts
Calendar Grey July 12, 2025
Dist Debian Esm H88
Urgent Redis security patch tackles remote code execution and Denial of Service risks for Ubuntu.
Two issues were discovered in Redis, the key-value database: * CVE-2025-32023: An authenticated user may have used a specially-crafted string to trigger a stack/heap out-of-bounds

Summary

* CVE-2025-32023: An authenticated user may have used a
specially-crafted string to trigger a stack/heap out-of-bounds
write during hyperloglog operations, potentially leading to a
remote code execution vulnerability. Installations that used Redis'
ACL system to restrict hyperloglog HLL commands are unaffected by
this issue.

* CVE-2025-48367: An unauthenticated connection could have caused
repeated IP protocol errors, leading to client starvation and
ultimately become a Denial of Service (DoS) attack.

For Debian 11 bullseye, these problems have been fixed in version
5:6.0.16-1+deb11u7.

We recommend that you upgrade your redis packages.

For the detailed security status of redis please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/redis

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
important
Lowest
Low
Medium
High
Critical

Package: redis
Version: 5:6.0.16-1+deb11u7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here