Unrated severityNVD Advisory· Published Jul 7, 2025· Updated Jul 7, 2025
Redis DoS Vulnerability due to bad connection error handling
CVE-2025-48367
Description
Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/redis/redis/commit/bde62951accfc4bb0a516276fd0b4b307e140ce2mitrex_refsource_MISC
- github.com/redis/redis/releases/tag/6.2.19mitrex_refsource_MISC
- github.com/redis/redis/releases/tag/7.2.10mitrex_refsource_MISC
- github.com/redis/redis/releases/tag/7.4.5mitrex_refsource_MISC
- github.com/redis/redis/releases/tag/8.0.3mitrex_refsource_MISC
- github.com/redis/redis/security/advisories/GHSA-4q32-c38c-pwgqmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.