OESA-2025-1474

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1474
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-1474.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2025-1474
Upstream
Published
2025-05-09T12:42:23Z
Modified
2025-08-12T05:49:05.810865Z
Summary
redis security update
Details

Redis is an advanced key-value store. It is often referred to as a dattructure server since keys can contain strings, hashes ,lists, sets anorted sets.

Security Fix(es):

Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can cause unlimited growth of output buffers, until the server runs out of memory or is killed. By default, the Redis configuration does not limit the output buffer of normal clients (see client-output-buffer-limit). Therefore, the output buffer can grow unlimitedly over time. As a result, the service is exhausted and the memory is unavailable. When password authentication is enabled on the Redis server, but no password is provided, the client can still cause the output buffer to grow from "NOAUTH" responses until the system will run out of memory. This issue has been patched in version 7.4.3. An additional workaround to mitigate this problem without patching the redis-server executable is to block access to prevent unauthenticated users from connecting to Redis. This can be done in different ways. Either using network access control tools like firewalls, iptables, security groups, etc, or enabling TLS and requiring users to authenticate using client side certificates.(CVE-2025-21605)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / redis

Package

Name
redis
Purl
pkg:rpm/openEuler/redis&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.8-1.oe2003sp4

Ecosystem specific

{
    "src": [
        "redis-7.2.8-1.oe2003sp4.src.rpm"
    ],
    "aarch64": [
        "redis-7.2.8-1.oe2003sp4.aarch64.rpm",
        "redis-debuginfo-7.2.8-1.oe2003sp4.aarch64.rpm",
        "redis-debugsource-7.2.8-1.oe2003sp4.aarch64.rpm"
    ],
    "x86_64": [
        "redis-7.2.8-1.oe2003sp4.x86_64.rpm",
        "redis-debuginfo-7.2.8-1.oe2003sp4.x86_64.rpm",
        "redis-debugsource-7.2.8-1.oe2003sp4.x86_64.rpm"
    ]
}

openEuler:22.03-LTS-SP3 / redis

Package

Name
redis
Purl
pkg:rpm/openEuler/redis&distro=openEuler-22.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.8-1.oe2203sp3

Ecosystem specific

{
    "src": [
        "redis-7.2.8-1.oe2203sp3.src.rpm"
    ],
    "aarch64": [
        "redis-7.2.8-1.oe2203sp3.aarch64.rpm",
        "redis-debuginfo-7.2.8-1.oe2203sp3.aarch64.rpm",
        "redis-debugsource-7.2.8-1.oe2203sp3.aarch64.rpm"
    ],
    "x86_64": [
        "redis-7.2.8-1.oe2203sp3.x86_64.rpm",
        "redis-debuginfo-7.2.8-1.oe2203sp3.x86_64.rpm",
        "redis-debugsource-7.2.8-1.oe2203sp3.x86_64.rpm"
    ]
}

openEuler:22.03-LTS-SP4 / redis

Package

Name
redis
Purl
pkg:rpm/openEuler/redis&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.8-1.oe2203sp4

Ecosystem specific

{
    "src": [
        "redis-7.2.8-1.oe2203sp4.src.rpm"
    ],
    "aarch64": [
        "redis-7.2.8-1.oe2203sp4.aarch64.rpm",
        "redis-debuginfo-7.2.8-1.oe2203sp4.aarch64.rpm",
        "redis-debugsource-7.2.8-1.oe2203sp4.aarch64.rpm"
    ],
    "x86_64": [
        "redis-7.2.8-1.oe2203sp4.x86_64.rpm",
        "redis-debuginfo-7.2.8-1.oe2203sp4.x86_64.rpm",
        "redis-debugsource-7.2.8-1.oe2203sp4.x86_64.rpm"
    ]
}

openEuler:24.03-LTS / redis

Package

Name
redis
Purl
pkg:rpm/openEuler/redis&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.8-1.oe2403sp1

Ecosystem specific

{
    "src": [
        "redis-7.2.8-1.oe2403.src.rpm",
        "redis-7.2.8-1.oe2403sp1.src.rpm"
    ],
    "aarch64": [
        "redis-7.2.8-1.oe2403.aarch64.rpm",
        "redis-debuginfo-7.2.8-1.oe2403.aarch64.rpm",
        "redis-debugsource-7.2.8-1.oe2403.aarch64.rpm",
        "redis-7.2.8-1.oe2403sp1.aarch64.rpm",
        "redis-debuginfo-7.2.8-1.oe2403sp1.aarch64.rpm",
        "redis-debugsource-7.2.8-1.oe2403sp1.aarch64.rpm"
    ],
    "x86_64": [
        "redis-7.2.8-1.oe2403.x86_64.rpm",
        "redis-debuginfo-7.2.8-1.oe2403.x86_64.rpm",
        "redis-debugsource-7.2.8-1.oe2403.x86_64.rpm",
        "redis-7.2.8-1.oe2403sp1.x86_64.rpm",
        "redis-debuginfo-7.2.8-1.oe2403sp1.x86_64.rpm",
        "redis-debugsource-7.2.8-1.oe2403sp1.x86_64.rpm"
    ]
}

openEuler:24.03-LTS-SP1 / redis

Package

Name
redis
Purl
pkg:rpm/openEuler/redis&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.8-1.oe2403sp1

Ecosystem specific

{
    "src": [
        "redis-7.2.8-1.oe2403sp1.src.rpm"
    ],
    "aarch64": [
        "redis-7.2.8-1.oe2403sp1.aarch64.rpm",
        "redis-debuginfo-7.2.8-1.oe2403sp1.aarch64.rpm",
        "redis-debugsource-7.2.8-1.oe2403sp1.aarch64.rpm"
    ],
    "x86_64": [
        "redis-7.2.8-1.oe2403sp1.x86_64.rpm",
        "redis-debuginfo-7.2.8-1.oe2403sp1.x86_64.rpm",
        "redis-debugsource-7.2.8-1.oe2403sp1.x86_64.rpm"
    ]
}