V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2025-32023
ANC
HighConfirmedExploit available

Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated us…

CVSS
7.8
High
EPSS
0.18
p95
Published
2025-01-01
Updated
2025-01-01
Description

Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. The bug likely affects all Redis versions with hyperloglog operations implemented. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing hyperloglog operations. This can be done using ACL to restrict HLL commands.

Tags · CWE
CWE-680
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-67
CAPEC-92
CAPEC-100
Affected products
Redis 2.8.0–6.2.19Redis 7.2.0–7.2.10Redis 7.4.0–7.4.5Redis 8.0.0–8.0.3
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.184 · p95
Known exploited (KEV)
No
Known exploits — Сканер-ВС
52477
exploitdb · https://www.exploit-db.com/exploits/52477
Enterprise
CVE-2025-32023
github-poc · https://github.com/44528zja/Blackash-CVE-2025-32023
Enterprise
Affected software
ProductVendorStatus
Tracked
Tracked
Tracked
redictTracked
redictTracked
redictTracked
redisTracked
redisTracked
redisTracked
redisTracked
redisTracked
redisTracked
valkeyTracked
valkeyTracked
valkeyTracked
redis*Tracked
Source databases
ANC
DEB
CVE
UBU
Related vulnerabilities