RHSA-2025:11401: Important: valkey security update

Published Jul 21, 2025
·
Updated

Important: valkey security update

Other sources

Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.Security Fix(es): redis: Redis Stack Buffer Overflow (CVE-2025-27151) redis: Redis Unauthenticated Denial of Service (CVE-2025-48367) redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability (CVE-2025-32023) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Red Hat

Affected Software

28 affected componentsFixes available
Red Hat Red Hat Enterprise Linux for IBM z Systems - 4 years of updates
Red Hat Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Red Hat Enterprise Linux for Power, little endian - 4 years of support
Red Hat Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Red Hat Enterprise Linux for ARM 64 - 4 years of updates
Red Hat Red Hat Enterprise Linux for IBM z Systems
Red Hat Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Red Hat Enterprise Linux for x86_64
Red Hat Red Hat Enterprise Linux for ARM 64
Red Hat Red Hat Enterprise Linux for x86_64 - 4 years of updates
Red Hat Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Red Hat Enterprise Linux for Power, little endian
redhat/valkey<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey-debuginfo<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey-debugsource<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey-devel<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey-debuginfo<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey-debugsource<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey-devel<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey-devel<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey-debuginfo<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey-debugsource<8.0.4-1.el10_0
8.0.4-1.el10_0
redhat/valkey<8.0.4-1.el10_0.aa
8.0.4-1.el10_0.aa
redhat/valkey-debuginfo<8.0.4-1.el10_0.aa
8.0.4-1.el10_0.aa
redhat/valkey-debugsource<8.0.4-1.el10_0.aa
8.0.4-1.el10_0.aa
redhat/valkey-devel<8.0.4-1.el10_0.aa
8.0.4-1.el10_0.aa

Remediation

Event History

Jul 21, 2025
Advisory Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionAffected Software
Advisory Published
via Red Hat·01:00 AM
Data Sourced
via Red Hat·01:00 AM
Severity

Frequently Asked Questions

1

What is the severity of RHSA-2025:11401?

RHSA-2025:11401 is classified as an important security update.

2

How do I fix RHSA-2025:11401?

To fix RHSA-2025:11401, you should update the valkey package to version 8.0.4-1.el10_0 or later.

3

What products are affected by RHSA-2025:11401?

RHSA-2025:11401 affects several versions of Red Hat Enterprise Linux across multiple architectures.

4

What specific package needs to be updated for RHSA-2025:11401?

The specific package that needs to be updated for RHSA-2025:11401 is the valkey package.

5

Is there a debug package associated with RHSA-2025:11401?

Yes, there is a valkey-debuginfo package that should also be updated as part of addressing RHSA-2025:11401.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203