Database/Control plane, storage & DevOps
Redis: Authenticated user triggers a stack/heap out-of-bounds write in hyperloglog ops
CVSS 7.0CVE-2025-32023Control plane, storage & DevOpscurated
Impact
Authenticated user triggers a stack/heap out-of-bounds write in hyperloglog ops -> potential RCE
Who can reach it
Local
What to do
Control-plane: upgrade to 8.0.3/7.4.5/7.2.10/6.2.19; restrict the command surface
References
Related entries
- Redis: Malformed ACL selector triggers a server panicCVE-2024-51741 · RedisMedium
- Redis: Lua environment weakness lets a user inject code that runs with another Redis user's privilegesCVE-2022-24735 · RedisLow
- Redis: Crafted Lua script triggers a NULL pointer dereferenceCVE-2022-24736 · RedisLow
- Redis: Debian/Ubuntu packaging leaves a Lua sandbox escapeCVE-2022-0543 · RedisCritical
- Redis: "RediShell" - authenticated user crafts a Lua script to trigger a use-after-freeCVE-2025-49844 · RedisCritical
- Sidero Omni: SAML assertion replay race lets a captured saml-session token be redeemed more than onceCVE-2026-45720 · Sidero Omni (SAML session interceptor, internal/pkg/auth/interceptor/saml.go)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.