openSUSE-SU-2025:20121-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:20121-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2025:20121-1
Upstream
CVE (5)
Related
Published
2025-12-30T17:05:45Z
Modified
2026-03-12T02:06:45Z
Summary
Security update for redis
Details

This update for redis fixes the following issues:

  • Updated to 8.2.3 (boo#1252996 CVE-2025-62507)

    • Security fixes
      • (CVE-2025-62507) Bug in XACKDEL may lead to stack overflow and potential RCE
    • Bug fixes
      • HGETEX: A missing numfields argument when FIELDS is used can lead to Redis crash
      • An overflow in HyperLogLog with 2GB+ entries may result in a Redis crash
      • Cuckoo filter - Division by zero in Cuckoo filter insertion
      • Cuckoo filter - Counter overflow
      • Bloom filter - Arbitrary memory read/write with invalid filter
      • Bloom filter - Out-of-bounds access with empty chain
      • Top-k - Out-of-bounds access
      • Bloom filter - Restore invalid filter [We thank AWS security for responsibly disclosing the security bug]
  • Updated to 8.2.2 (boo#1250995)

    • https://github.com/redis/redis/releases/tag/8.2.2
    • Fixed Lua script may lead to remote code execution (CVE-2025-49844).
    • Fixed Lua script may lead to integer overflow (CVE-2025-46817).
    • Fixed Lua script can be executed in the context of another user (CVE-2025-46818).
    • Fixed LUA out-of-bound read (CVE-2025-46819).
    • Fixed potential crash on Lua script or streams and HFE defrag.
    • Fixed potential crash when using ACL rules.
    • Added VSIM: new EPSILON argument to specify maximum distance.
    • Added SVS-VAMANA: allow use of BUILD_INTEL_SVS_OPT flag.
    • Added RESP3 serialization performance.
    • Added INFO SEARCH: new SVS-VAMANA metrics.
  • Updated to 8.2.1

    • Bug fixes
      • #14240 INFO KEYSIZES - potential incorrect histogram updates on cluster mode with modules
      • #14274 Disable Active Defrag during flushing replica
      • #14276 XADD or XTRIM can crash the server after loading RDB
      • #Q6601 Potential crash when running FLUSHDB (MOD-10681)
    • Performance and resource utilization
      • Query Engine - LeanVec and LVQ proprietary Intel optimizations were removed from Redis Open Source
      • #Q6621 Fix regression in INFO (MOD-10779)
References

Affected packages

openSUSE:Leap 16.0 / redis

Package

Name
redis
Purl
pkg:rpm/opensuse/redis&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.2.3-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "redis":  "8.2.3-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:20121-1.json"