Red Hat Security Advisory: redis security update
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log. Security Fix(es): * redis: Redis Unauthenticated Denial of Service (CVE-2025-48367) * redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability (CVE-2025-32023) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
The advisory covers two vulnerabilities in Redis 6.2.7-1.el9_2.4 as distributed by Red Hat for Red Hat Enterprise Linux 9.2. CVE-2025-48367 is an unauthenticated denial of service vulnerability, allowing potential disruption without authentication. CVE-2025-32023 is an out-of-bounds write vulnerability in the Hyperloglog data structure implementation, which could lead to memory corruption. Red Hat has rated the update as important and provided updated packages to remediate these issues. The advisory references further details on the CVE pages but does not provide CVSS scores or detailed exploitation information. The vulnerabilities are addressed by applying the updated Redis packages provided by Red Hat.
Potential Impact
The unauthenticated denial of service vulnerability (CVE-2025-48367) could allow an attacker to disrupt Redis service availability without authentication. The out-of-bounds write vulnerability (CVE-2025-32023) could lead to memory corruption, potentially causing crashes or other unintended behavior. Both vulnerabilities affect Redis as packaged for Red Hat Enterprise Linux 9.2 and could impact systems running these versions if unpatched. There are no known exploits in the wild at this time according to the advisory.
Mitigation Recommendations
Red Hat has released updated Redis packages for Red Hat Enterprise Linux 9.2 to address these vulnerabilities. Users should apply the security update redis-6.2.7-1.el9_2.4 from Red Hat's official repositories or errata to remediate these issues. Detailed update instructions are available at https://access.redhat.com/articles/11258. No alternative mitigations or workarounds are specified in the advisory. Patch status is confirmed by the vendor advisory as an official fix.
Red Hat Security Advisory: redis security update
Description
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log. Security Fix(es): * redis: Redis Unauthenticated Denial of Service (CVE-2025-48367) * redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability (CVE-2025-32023) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The advisory covers two vulnerabilities in Redis 6.2.7-1.el9_2.4 as distributed by Red Hat for Red Hat Enterprise Linux 9.2. CVE-2025-48367 is an unauthenticated denial of service vulnerability, allowing potential disruption without authentication. CVE-2025-32023 is an out-of-bounds write vulnerability in the Hyperloglog data structure implementation, which could lead to memory corruption. Red Hat has rated the update as important and provided updated packages to remediate these issues. The advisory references further details on the CVE pages but does not provide CVSS scores or detailed exploitation information. The vulnerabilities are addressed by applying the updated Redis packages provided by Red Hat.
Potential Impact
The unauthenticated denial of service vulnerability (CVE-2025-48367) could allow an attacker to disrupt Redis service availability without authentication. The out-of-bounds write vulnerability (CVE-2025-32023) could lead to memory corruption, potentially causing crashes or other unintended behavior. Both vulnerabilities affect Redis as packaged for Red Hat Enterprise Linux 9.2 and could impact systems running these versions if unpatched. There are no known exploits in the wild at this time according to the advisory.
Mitigation Recommendations
Red Hat has released updated Redis packages for Red Hat Enterprise Linux 9.2 to address these vulnerabilities. Users should apply the security update redis-6.2.7-1.el9_2.4 from Red Hat's official repositories or errata to remediate these issues. Detailed update instructions are available at https://access.redhat.com/articles/11258. No alternative mitigations or workarounds are specified in the advisory. Patch status is confirmed by the vendor advisory as an official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:12478
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-48367"]
Threat ID: 6a419cb827e9c79719abddc8
Added to database: 06/28/2026, 22:14:16 UTC
Last enriched: 08/07/2026, 01:01:41 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.