RHSA-2025:12769: Important: redis:6 security update
Important: redis:6 security update
Other sources
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log.Security Fix(es): redis: Redis Unauthenticated Denial of Service (CVE-2025-48367) redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability (CVE-2025-32023) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 6.0.9-5.module+el8.6.0+23376+7886a418.5 - Upgrade
Upgrade
redhat/redis-debuginfoto a version that resolves this vulnerability.Fixed in 6.0.9-5.module+el8.6.0+23376+7886a418.5 - Upgrade
Upgrade
redhat/redis-debugsourceto a version that resolves this vulnerability.Fixed in 6.0.9-5.module+el8.6.0+23376+7886a418.5 - Upgrade
Upgrade
redhat/redis-develto a version that resolves this vulnerability.Fixed in 6.0.9-5.module+el8.6.0+23376+7886a418.5 - Upgrade
Upgrade
redhat/redis-docto a version that resolves this vulnerability.Fixed in 6.0.9-5.module+el8.6.0+23376+7886a418.5 - Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 6.0.9-5.module+el8.6.0+23376+7886a418.5.aa - Upgrade
Upgrade
redhat/redis-debuginfoto a version that resolves this vulnerability.Fixed in 6.0.9-5.module+el8.6.0+23376+7886a418.5.aa - Upgrade
Upgrade
redhat/redis-debugsourceto a version that resolves this vulnerability.Fixed in 6.0.9-5.module+el8.6.0+23376+7886a418.5.aa - Upgrade
Upgrade
redhat/redis-develto a version that resolves this vulnerability.Fixed in 6.0.9-5.module+el8.6.0+23376+7886a418.5.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:12769?
The severity of RHSA-2025:12769 is classified as important.
How do I fix RHSA-2025:12769?
To fix RHSA-2025:12769, you should update the Redis package to version 6.0.9-5.module+el8.6.0+23376+7886a418.5.
Which systems are affected by RHSA-2025:12769?
RHSA-2025:12769 affects multiple versions of Red Hat Enterprise Linux Server and related packages.
What is the purpose of the Redis update in RHSA-2025:12769?
The purpose of the Redis update in RHSA-2025:12769 is to address security vulnerabilities and enhance the performance of the Redis key-value store.
Is it mandatory to apply the patch for RHSA-2025:12769?
While it is not legally mandatory, applying the patch for RHSA-2025:12769 is highly recommended to ensure security and stability.