Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia: Significant Security Patch Released for Redis MGASA-2025-0211

mageia
Calendar Grey July 19, 2025
Dist Mageia Esm H88
The latest updates to Redis packages for Mageia tackle critical vulnerabilities and adjustments in functionality that have emerged in newer releases.
Updated redis packages to a more recent version to fix security vulnerabilities: Some vulnerabilities have been discovered and fixed

Summary

Updated redis packages to a more recent version to fix security vulnerabilities: Some vulnerabilities have been discovered and fixed. Please note this update is from 7.0 to 7.2 which brings some potentially breaking changes. In most cases this update could be installed without problems. Potentially Breaking / Behavior Changes: * Client side tracking for scripts now tracks the keys that are read by the script instead of the keys that are declared by the caller of EVAL / FCALL (#11770) * Freeze time sampling during command execution and in scripts (#10300) * When a blocked command is being unblocked, checks like ACL, OOM, etc are re-evaluated (#11012) * Unify ACL failure error message text and error codes (#11160) * Blocked stream command that's released when key no longer exists carries a different error code (#11012) * Command stats are updated for blocked commands only when / if the command actually executes (#11012) * The way ACL users are stored internally no longer rem...

References

- https://bugs.mageia.org/show_bug.cgi?id=34452

- https://github.com/redis/redis/releases/tag/7.2.10

- https://www.cve.org/CVERecord?id=CVE-2025-27151

- https://www.cve.org/CVERecord?id=CVE-2023-41056

- https://www.cve.org/CVERecord?id=CVE-2025-32023

- https://www.cve.org/CVERecord?id=CVE-2025-48367

Resolution

SRPMS

- 9/core/redis-7.2.10-1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 19 Jul 2025
URL: https://advisories.mageia.org/MGASA-2025-0211.html
Type: security
CVE: CVE-2025-27151, CVE-2023-41056, CVE-2025-32023, CVE-2025-48367

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here