Home / mailingsPDF  

[USN-7824-3] Redis vulnerability

Posted on 16 October 2025
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-7824-3
October 16, 2025

redis vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

Redis could be made to crash or run programs if it received
specially crafted network traffic from an authenticated user.

Software Description:
- redis: Persistent key-value database with network interface

Details:

USN-7824-1 fixed several vulnerabilities in Redis. This update provides
the corresponding update for Ubuntu 22.04 LTS.

Original advisory details:

Benny Isaacs, Nir Brakha, and Sagi Tzadik discovered that Redis incorrectly
handled memory when running Lua scripts. An authenticated attacker could use
this vulnerability to trigger a use-after-free condition, and potentially
achieve remote code execution on the Redis server.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
redis 5:6.0.16-1ubuntu1.1
redis-sentinel 5:6.0.16-1ubuntu1.1
redis-server 5:6.0.16-1ubuntu1.1
redis-tools 5:6.0.16-1ubuntu1.1

After a standard system update you need to restart Redis to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7824-3
https://ubuntu.com/security/notices/USN-7824-2
https://ubuntu.com/security/notices/USN-7824-1
CVE-2025-49844

Package Information:
https://launchpad.net/ubuntu/+source/redis/5:6.0.16-1ubuntu1.1

--===============1892794560941914237==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP