Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian LTS 11: Redis Important RCE DoS Risks DLA-4325-1 CVE-2025-46817

debian lts
Calendar Grey October 9, 2025
Dist Debian Esm H88
Multiple vulnerabilities fixed in Redis for Debian LTS, impacting server integrity and user safety.
Multiple vulnerabilities were discovered in Redis, a popular key/value database: * CVE-2025-46817: Fix an issue where an authenticated user could have

Summary

* CVE-2025-46817: Fix an issue where an authenticated user could have
used a specially-crafted Lua script to cause an integer overflow
and potentially lead to remote code execution.

* CVE-2025-46819: Address a potential vulnerability where an
authenticated user could have used a specially-crafted Lua script
to read out-of-bound data and/or crash the server and thereby
create a denial of service attack.

* CVE-2025-49844: Fix an issue where authenticated users could have
exploited a specially-crafted Lua script to manipulate the garbage
collector, trigger a use-after-free and potentially lead to remote
code execution.

For Debian 11 bullseye, these problems have been fixed in version
5:6.0.16-1+deb11u8.

We recommend that you upgrade your redis packages.

For the detailed security status of redis please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/redis

Further information about Debian LTS security advisories, how to apply

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Package: redis
Version: 5:6.0.16-1+deb11u8
Debian Bug: 1117553

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here