Last updated 20 March 2025
Lua library commands may lead to stack overflow and RCE in Redis
Redis has been upgraded to version 7.0.15 to mitigate CVE-2023-41056.
Redis allows out of bounds writes in hyperloglog commands leading to RCE
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from processCommandAndResetClient when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
Denial-of-service due to unbounded pattern matching in Redis
CVE-2023-45145 - The wrong order of listen(2) and chmod(2) calls creates a race condition that can be used by another process to bypass desired Unix socket permissions on startup.
Upstream have released version 7.0.14/7.2.2 to fix CVE-2023-45145.
Reference: - https://github.com/redis/redis/releases/tag/7.0.14 - https://bugs.mageia.org/32406