[ALSA-2025:7429] Important: redis:7 security update
Type:
security
Severity:
important
Release date:
2025-05-21
Description:
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log. Security Fix(es): * redis: Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client (CVE-2025-21605) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 redis-devel-7.2.8-1.module_el9.6.0+168+b8d8e900.aarch64.rpm 1e9dbb7c908fcc4219ea4926871ce3c3d74f597c6fa83476d0dcf77f4134fff9
aarch64 redis-7.2.8-1.module_el9.6.0+168+b8d8e900.aarch64.rpm dbfe1c12fd3a5b225736703385a321a153af5716b2a55581421dfea9e8c51bb4
noarch redis-doc-7.2.8-1.module_el9.6.0+168+b8d8e900.noarch.rpm 85258f80ee5fce874b978c6ba6d16bc5341167a148e6bdb4ea5186e05c6d2623
ppc64le redis-7.2.8-1.module_el9.6.0+168+b8d8e900.ppc64le.rpm 4703acf347b0feabfbcf2cdf1a9b97cc822791aca638aff521f71af60f7a89f0
ppc64le redis-devel-7.2.8-1.module_el9.6.0+168+b8d8e900.ppc64le.rpm a58edea71124cb5cabdbe9692a2d74a3a9789ef968e1d5a164e718d2a9dc5eb5
s390x redis-devel-7.2.8-1.module_el9.6.0+168+b8d8e900.s390x.rpm 7bd40a979abf54ea58247a015835d658b8f11be409cb2ea9335613acea9fec24
s390x redis-7.2.8-1.module_el9.6.0+168+b8d8e900.s390x.rpm 85229fd47ee2355f45f52d9f854784b13caf168d33bb60764158c426c33df4fe
x86_64 redis-devel-7.2.8-1.module_el9.6.0+168+b8d8e900.x86_64.rpm 428de1f8ca8677646d02039c4dee9e118301aa5f738c185555890be3b564ce39
x86_64 redis-7.2.8-1.module_el9.6.0+168+b8d8e900.x86_64.rpm 9bbf32e65965d3e4c44154d35b19748919184a7be3c5cf1462da96502b6a29cc
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.