Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE: Essential Security Fix 2025-20121-1 for RCE and Buffer Overflow

opensuse
Calendar Grey November 28, 2025
Dist Opensuse Esm H88
Critical security update for openSUSE redis addresses five issues, including potential remote code execution.
An update that solves 5 vulnerabilities and has 2 bug fixes can now be installed.

Description

This update for redis fixes the following issues:

- Updated to 8.2.3 (boo#1252996 CVE-2025-62507)

* https://github.com/redis/redis/releases/tag/8.2.3

- Security fixes

- (CVE-2025-62507) Bug in `XACKDEL` may lead to stack overflow

and potential RCE

- Bug fixes

- `HGETEX`: A missing `numfields` argument when `FIELDS` is

used can lead to Redis crash

- An overflow in `HyperLogLog` with 2GB+ entries may result in

a Redis crash

- Cuckoo filter - Division by zero in Cuckoo filter insertion

- Cuckoo filter - Counter overflow

- Bloom filter - Arbitrary memory read/write with invalid

filter

- Bloom filter - Out-of-bounds access with empty chain

- Top-k - Out-of-bounds access

- Bloom filter - Restore invalid filter [We thank AWS security

for responsibly disclosing the security bug]

- Updated to 8.2.2 (boo#1250995)

* https://github.com/redis/redis/releases/tag/8.2.2

* Fixed Lua script may lead to remote code execution...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

redis-8.2.0-bp160.1.3

References

* bsc#1250995

* bsc#1252996

References:

* https://www.suse.com/security/cve/CVE-2025-46817.html

* https://www.suse.com/security/cve/CVE-2025-46818.html

* https://www.suse.com/security/cve/CVE-2025-46819.html

* https://www.suse.com/security/cve/CVE-2025-49844.html

* https://www.suse.com/security/cve/CVE-2025-62507.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025-20121-1
Rating: critical
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here