<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:31:31.055948+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:11401</id>
    <title>ALSA-2025:11401 — Important: valkey security update</title>
    <updated>2026-10-02T19:31:31.070651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: valkey, AlmaLinux:10: valkey-devel</p>
<p>Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.</p>
<p>Security Fix(es):</p>
<p>* redis: Redis Stack Buffer Overflow (CVE-2025-27151)
  * redis: Redis Unauthenticated Denial of Service (CVE-2025-48367)
  * redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability (CVE-2025-32023)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:11401"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08608</id>
    <title>bdu:2025-08608</title>
    <updated>2026-10-02T19:31:31.070719+00:00</updated>
    <content>bdu:2025-08608</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08608"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-27151</id>
    <title>BELL-CVE-2025-27151</title>
    <updated>2026-10-02T19:31:31.070737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: redis, Alpaquita:stream: redis</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-27151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keydb-2025-27151</id>
    <title>BIT-keydb-2025-27151 — redis-check-aof may lead to stack overflow and potential RCE</title>
    <updated>2026-10-02T19:31:31.070755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keydb</p>
<p>Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keydb-2025-27151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0585</id>
    <title>certfr-2025-avi-0585 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Certaines d'entre elles permettent à un attaquant de…</title>
    <updated>2026-10-02T19:31:31.070776+00:00</updated>
    <content>certfr-2025-avi-0585</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241717</id>
    <title>EUVD-2026-241717</title>
    <updated>2026-10-02T19:31:31.070791+00:00</updated>
    <content>EUVD-2026-241717</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27151</id>
    <title>fkie_cve-2025-27151</title>
    <updated>2026-10-02T19:31:31.070801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-27151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-27151</id>
    <title>msrc_CVE-2025-27151 — redis-check-aof may lead to stack overflow and potential RCE</title>
    <updated>2026-10-02T19:31:31.070821+00:00</updated>
    <content>msrc_CVE-2025-27151</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-27151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1630</id>
    <title>OESA-2025-1630 — redis security update</title>
    <updated>2026-10-02T19:31:31.070835+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: redis, openEuler:22.03-LTS-SP4: redis, openEuler:24.03-LTS: redis, openEuler:24.03-LTS-SP1: redis, openEuler:20.03-LTS-SP4: redis</p>
<p>Redis is an advanced key-value store. It is often referred to as a dattructure server since keys can contain strings, hashes ,lists, sets anorted sets.

Security Fix(es):</p>
<p>Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.(CVE-2025-27151)</p>
<p>setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev-&amp;gt;size - prev-&amp;gt;used.(CVE-2025-49112)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15293-1</id>
    <title>openSUSE-SU-2025:15293-1 — redis-8.0.2-1.1 on GA media</title>
    <updated>2026-10-02T19:31:31.070865+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>redis-8.0.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15293-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02190-1</id>
    <title>SUSE-SU-2025:02190-1 — Security update for redis</title>
    <updated>2026-10-02T19:31:31.070881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for redis</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02190-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-27151</id>
    <title>UBUNTU-CVE-2025-27151</title>
    <updated>2026-10-02T19:31:31.070895+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: redis</p>
<p>Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-27151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1150</id>
    <title>WID-SEC-W-2025-1150 — Redis: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T19:31:31.070912+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Redis ausnutzen, um einen Denial of Service herbeizuführen und poteziell beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1150"/>
  </entry>
</feed>
