<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:57:49 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:11401 — Important: valkey security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:11401</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: valkey, AlmaLinux:10: valkey-devel&lt;/p&gt;
&lt;p&gt;Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* redis: Redis Stack Buffer Overflow (CVE-2025-27151)
  * redis: Redis Unauthenticated Denial of Service (CVE-2025-48367)
  * redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability (CVE-2025-32023)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: valkey, AlmaLinux:10: valkey-devel&lt;/p&gt;
&lt;p&gt;Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* redis: Redis Stack Buffer Overflow (CVE-2025-27151)
  * redis: Redis Unauthenticated Denial of Service (CVE-2025-48367)
  * redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability (CVE-2025-32023)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:11401</guid>
    </item>
    <item>
      <title>bdu:2025-09081</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09081</link>
      <description>bdu:2025-09081</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09081</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-48367</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-48367</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: redis, Alpaquita:25: redis, Alpaquita:stream: redis&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: redis, Alpaquita:25: redis, Alpaquita:stream: redis&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-48367</guid>
    </item>
    <item>
      <title>BIT-keydb-2025-48367 — Redis DoS Vulnerability due to bad connection error handling</title>
      <link>https://cve.radiocsirt.org/vuln/bit-keydb-2025-48367</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keydb&lt;/p&gt;
&lt;p&gt;Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keydb&lt;/p&gt;
&lt;p&gt;Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-keydb-2025-48367</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1125 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</link>
      <description>certfr-2026-avi-1125</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</guid>
    </item>
    <item>
      <title>cnvd-2025-16525</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-16525</link>
      <description>cnvd-2025-16525</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-16525</guid>
    </item>
    <item>
      <title>EUVD-2026-246474</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-246474</link>
      <description>EUVD-2026-246474</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-246474</guid>
    </item>
    <item>
      <title>fkie_cve-2025-48367</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48367</link>
      <description>&lt;p&gt;Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-48367</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-48367 — Redis DoS Vulnerability due to bad connection error handling</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-48367</link>
      <description>msrc_CVE-2025-48367</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-48367</guid>
    </item>
    <item>
      <title>OESA-2025-1850 — redis security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1850</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: redis, openEuler:20.03-LTS-SP4: redis, openEuler:22.03-LTS-SP3: redis, openEuler:22.03-LTS-SP4: redis, openEuler:24.03-LTS: redis, openEuler:24.03-LTS-SP1: redis&lt;/p&gt;
&lt;p&gt;Redis is an advanced key-value store. It is often referred to as a dattructure server since keys can contain strings, hashes ,lists, sets anorted sets.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. The bug likely affects all Redis versions with hyperloglog operations implemented. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing hyperloglog operations. This can be done using ACL to restrict HLL commands.(CVE-2025-32023)&lt;/p&gt;
&lt;p&gt;Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.(CVE-2025-48367)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: redis, openEuler:20.03-LTS-SP4: redis, openEuler:22.03-LTS-SP3: redis, openEuler:22.03-LTS-SP4: redis, openEuler:24.03-LTS: redis, openEuler:24.03-LTS-SP1: redis&lt;/p&gt;
&lt;p&gt;Redis is an advanced key-value store. It is often referred to as a dattructure server since keys can contain strings, hashes ,lists, sets anorted sets.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. The bug likely affects all Redis versions with hyperloglog operations implemented. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing hyperloglog operations. This can be done using ACL to restrict HLL commands.(CVE-2025-32023)&lt;/p&gt;
&lt;p&gt;Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.(CVE-2025-48367)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1850</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15318-1 — redis-8.0.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15318-1</link>
      <description>&lt;p&gt;redis-8.0.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;redis-8.0.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15318-1</guid>
    </item>
    <item>
      <title>RHSA-2025:12468 — Red Hat Security Advisory: redis security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:12468</link>
      <description>&lt;p&gt;redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability redis: Redis Unauthenticated Denial of Service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability redis: Redis Unauthenticated Denial of Service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:12468</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02579-1 — Security update for redis</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02579-1</link>
      <description>&lt;p&gt;Security update for redis&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for redis&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02579-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-48367</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48367</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: redis, Ubuntu:Pro:16.04:LTS: redis, Ubuntu:Pro:18.04:LTS: redis, Ubuntu:Pro:20.04:LTS: redis, Ubuntu:Pro:22.04:LTS: redis, Ubuntu:24.04:LTS: redis, Ubuntu:24.04:LTS: valkey, Ubuntu:25.10: redict, Ubuntu:25.10: redis, Ubuntu:26.04:LTS: redict and 1 more&lt;/p&gt;
&lt;p&gt;Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: redis, Ubuntu:Pro:16.04:LTS: redis, Ubuntu:Pro:18.04:LTS: redis, Ubuntu:Pro:20.04:LTS: redis, Ubuntu:Pro:22.04:LTS: redis, Ubuntu:24.04:LTS: redis, Ubuntu:24.04:LTS: valkey, Ubuntu:25.10: redict, Ubuntu:25.10: redis, Ubuntu:26.04:LTS: redict and 1 more&lt;/p&gt;
&lt;p&gt;Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48367</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1463 — Redis: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1463</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Redis ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Redis ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1463</guid>
    </item>
  </channel>
</rss>
