[ALSA-2025:0693] Important: redis security update
Type:
security
Severity:
important
Release date:
2025-01-29
Description:
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log. Security Fix(es): * redis: heap overflow in the lua cjson and cmsgpack libraries (CVE-2022-24834) * redis: possible bypass of Unix socket permissions on startup (CVE-2023-45145) * redis: Lua library commands may lead to stack overflow and RCE in Redis (CVE-2024-31449) * redis: Denial-of-service due to unbounded pattern matching in Redis (CVE-2024-31228) * redis: Redis' Lua library commands may lead to remote code execution (CVE-2024-46981) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 redis-devel-6.2.17-1.el9_5.aarch64.rpm 7ac38721311bc5285e1fa72a8a5dc2312f0564168bde48c5826977e0705d5dfe
aarch64 redis-6.2.17-1.el9_5.aarch64.rpm 90cbb48608c063e67d0b4041b64df6d168d17010c59c5a1a055e000f18783580
i686 redis-devel-6.2.17-1.el9_5.i686.rpm d96735a0cd672ff4e813b06cff923110a5a20369ae7baacf0fc2abe9324e260a
noarch redis-doc-6.2.17-1.el9_5.noarch.rpm 54c3cc22155c670b53674226da0b9dfa7cb677202584e77e691154b3c4c9c697
ppc64le redis-devel-6.2.17-1.el9_5.ppc64le.rpm b77295a706b2182c75564a48419c2b11d555a34f2edc41b399a7f38698843d35
ppc64le redis-6.2.17-1.el9_5.ppc64le.rpm f0e34c1e087db601f873ee7e2dc0a9d041db0eb4f5311c6d447575d8d106a2cc
s390x redis-devel-6.2.17-1.el9_5.s390x.rpm 82d3e8639efe4036c70e10fc1e4ecbd5fcdd55351eadcbfcd8d0625ea29dc83f
s390x redis-6.2.17-1.el9_5.s390x.rpm 8961213bb15d278bb5c1d30256c8d3dfe22a4fc2cbdb6fbecd97e93ae676f6e8
x86_64 redis-6.2.17-1.el9_5.x86_64.rpm 3add823940c4f1b72fa4de24d035be5eba9aac0d5c2e86b10553d1604004e77c
x86_64 redis-devel-6.2.17-1.el9_5.x86_64.rpm e7a27bb700f47c63faafdf50db56ea7164d3223c8420a790b6c83b896ae4c214
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.