RHSA-2025:0693HighCVSS 7.0
Red Hat Security Advisory: redis security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2022-24834 — redis: heap overflow in the lua cjson and cmsgpack libraries CVE-2023-45145 — redis: possible bypass of Unix socket permissions on startup CVE-2024-31228 — redis: Denial-of-service due to unbounded pattern matching in Redis CVE-2024-31449 — redis: Lua library commands may lead to stack overflow and RCE in Redis CVE-2024-46981 — redis: Redis' Lua library commands may lead to remote code execution
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2025:0693
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221662
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244940
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317056
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317058
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2336004
- externalhttps://issues.redhat.com/browse/RHEL-26627
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0693.json