CVE-2025-48367: Redis DoS Vulnerability due to bad connection error handling
Redis DoS Vulnerability due to bad connection error handling
Other sources
Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48367?
CVE-2025-48367 has a critical severity due to its potential to cause denial of service via client starvation.
How do I fix CVE-2025-48367?
To fix CVE-2025-48367, upgrade Redis to version 8.0.3, 7.4.5, 7.2.10, or 6.2.19.
What impact does CVE-2025-48367 have on my Redis database?
CVE-2025-48367 can lead to repeated IP protocol errors resulting in a denial of service for the Redis database.
Is CVE-2025-48367 exploitable without authentication?
Yes, CVE-2025-48367 can be exploited through an unauthenticated connection.
What versions of Redis are affected by CVE-2025-48367?
CVE-2025-48367 affects Redis versions prior to 8.0.3, 7.4.5, 7.2.10, and 6.2.19.