CVE-2025-48367

high
Published 2025-07-21 Β· Modified 2025-07-28
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2025:12006: redis:6 security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description redis: Redis Unauthenticated Denial of Service Red Hat statement The severity of this vulnerability is rated Moderate as it does not impact system availability. The effects are confined to the application layer without compromising the underlying system stability. CVSS v3: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat…

Description

redis: Redis Unauthenticated Denial of Service

Red Hat statement

The severity of this vulnerability is rated Moderate as it does not impact system availability. The effects are confined to the application layer without compromising the underlying system stability.

CVSS v3: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10valkey-0:8.0.4-1.el10_0RHSA-2025:114012025-07-21T00:00:00Z
Red Hat Enterprise Linux 8redis:6-8100020250716063446.489197e6RHSA-2025:120062025-07-28T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportredis:6-8040020250801055559.522a0ee4RHSA-2025:127892025-08-04T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onredis:6-8040020250801055559.522a0ee4RHSA-2025:127892025-08-04T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportredis:6-8060020250731141235.ad008a3aRHSA-2025:127692025-08-04T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Serviceredis:6-8060020250731141235.ad008a3aRHSA-2025:127692025-08-04T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsredis:6-8060020250731141235.ad008a3aRHSA-2025:127692025-08-04T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Serviceredis:6-8080020250730132007.63b34585RHSA-2025:127682025-08-04T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsredis:6-8080020250730132007.63b34585RHSA-2025:127682025-08-04T00:00:00Z
Red Hat Enterprise Linux 9redis-0:6.2.19-1.el9_6RHSA-2025:114532025-07-21T00:00:00Z
Red Hat Enterprise Linux 9redis:7-9060020250716081121.9RHSA-2025:120082025-07-28T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsredis-0:6.2.6-1.el9_0.4RHSA-2025:124682025-07-31T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsredis-0:6.2.7-1.el9_2.4RHSA-2025:124782025-08-01T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportredis-0:6.2.7-1.el9_4.4RHSA-2025:125242025-08-04T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportredis:7-9040020250730125543.9RHSA-2025:128922025-08-05T00:00:00Z

Package state

ProductPackageState
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-dev-tools-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/de-minimal-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/de-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-supported-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-supported-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Affected
Red Hat Ansible Automation Platform 2automation-controllerAffected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Developer Hubrhdh/rhdh-rhel9-operatorNot affected
Red Hat Discovery 1discovery/discovery-server-rhel9Not affected
Red Hat Enterprise Linux 9valkeyNot affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-amd-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-aws-nvidia-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-azure-amd-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-azure-nvidia-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-gcp-nvidia-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-intel-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-nvidia-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/gemma-2-9b-itNot affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/gemma-2-9b-it-fp8Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/granite-3.1-8b-lab-v2.1Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/granite-3.1-8b-starter-v2.1Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/instructlab-amd-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/instructlab-nvidia-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/modelcar-gemma-2-9b-itNot affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/modelcar-gemma-2-9b-it-fp8Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/modelcar-granite-3-1-8b-lab-v2-1Not affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/modelcar-granite-3-1-8b-starter-v2-1Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-data-science-pipelines-argo-argoexec-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-feast-operator-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-feature-server-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-api-server-v2-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-driver-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-launcher-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9Not affected
Red Hat Quay 3quay/quay-rhel8Affected
Red Hat Satellite 6satellite/iop-advisor-engine-rhel9Not affected

Apply commands

bash fix
Apply RHSA-2025:11401 for Red Hat Enterprise Linux 10
yum update -y valkey
# or:
dnf upgrade -y valkey

Affected

VendorProductVersion
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Developer HubNot affected
redhatRed Hat Developer HubNot affected
redhatRed Hat Discovery 1Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected
redhatRed Hat Enterprise Linux AI (RHEL AI)Not affected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
suse slesaffected
rockylinux rocky9fixed
debian debianforkyfixed7.3.5+ds-1
debian debiansidfixed7.3.5+ds-1
debian debianbookwormfixed5:7.0.15-1~deb12u5
debian debianbullseyefixed5:6.0.16-1+deb11u7
debian debiantrixiefixed5:8.0.2-2
almalinux almalinux9fixedredis-devel-7.2.10-1.module_el9.6.0+173+efaf9205.aarch64.rpm
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.