RHSA-2026:33427: Important: redis:6 security update
Important: redis:6 security update
Other sources
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log.Security Fix(es): redis: RESTORE invalid memory access may allow remote code execution (CVE-2026-25243) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 6.2.7-1.module+el8.8.0+24465+9d14ca70.7 - Upgrade
Upgrade
redhat/redis-debuginfoto a version that resolves this vulnerability.Fixed in 6.2.7-1.module+el8.8.0+24465+9d14ca70.7 - Upgrade
Upgrade
redhat/redis-debugsourceto a version that resolves this vulnerability.Fixed in 6.2.7-1.module+el8.8.0+24465+9d14ca70.7 - Upgrade
Upgrade
redhat/redis-develto a version that resolves this vulnerability.Fixed in 6.2.7-1.module+el8.8.0+24465+9d14ca70.7 - Upgrade
Upgrade
redhat/redis-docto a version that resolves this vulnerability.Fixed in 6.2.7-1.module+el8.8.0+24465+9d14ca70.7
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:33427?
The severity of RHSA-2026:33427 is high, with a severity score of 7.
How do I fix RHSA-2026:33427?
To fix RHSA-2026:33427, update your Redis package to the latest version provided by Red Hat.
What systems are affected by RHSA-2026:33427?
RHSA-2026:33427 affects various Red Hat Enterprise Linux distributions that include Redis.
What are the risks associated with RHSA-2026:33427?
The risks associated with RHSA-2026:33427 include potential exploits that could lead to data corruption or unauthorized data access.
When was RHSA-2026:33427 published?
RHSA-2026:33427 was published on June 30, 2026.