Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-48367

Published: July 8, 2025Last modified: August 6, 2025

Description

Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Notes

https://github.com/redis/redis/commit/bde62951accfc4bb0a516276fd0b4b307e140ce2

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSredisFixed (7.0.15-r5)
25 LTSredisFixed (8.0.3-r0)
StreamredisFixed (8.0.3-r0)

References

ON THIS PAGE