PT-2025-17641 · Redis+8 · Redis+8

Polaris-Alioth

·

Published

2025-04-23

·

Updated

2026-01-21

·

CVE-2025-21605

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Redis versions 2.6 through 7.4.2
Description Redis is an open source, in-memory database that persists on disk. An unauthenticated client can cause unlimited growth of output buffers, until the server runs out of memory or is killed. By default, the Redis configuration does not limit the output buffer of normal clients. The output buffer can grow unlimitedly over time, exhausting the service and making memory unavailable. When password authentication is enabled on the Redis server, but no password is provided, the client can still cause the output buffer to grow from "NOAUTH" responses until the system will run out of memory.
Recommendations For versions 2.6 through 7.4.2, update to version 7.4.3 to resolve the issue. As a temporary workaround, consider blocking access to prevent unauthenticated users from connecting to Redis by using network access control tools like firewalls, iptables, security groups, etc, or enabling TLS and requiring users to authenticate using client side certificates.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2025:7429
ALSA-2025:7438
ALSA-2025:7509
ALSA-2025:7686
ALSA-2025_16880
ALSA-2025_7429
ALSA-2025_7438
ALSA-2025_7686
ALT-PU-2025-11673
ALT-PU-2025-13204
ALT-PU-2025-9764
ALT-PU-2025-9766
AZL-60939
BDU:2025-05997
BIT-KEYDB-2025-21605
BIT-REDIS-2025-21605
BIT-VALKEY-2025-21605
CESA-2025_7686
CVE-2025-21605
DLA-4162-1
ECHO-0928-6C8A-5D18
GHSA-R67F-P999-2GFF
INFSA-2025_7429
INFSA-2025_7438
INFSA-2025_7686
MGASA-2025-0171
OESA-2025-1474
OPENSUSE-SU-2025:15035-1
OPENSUSE-SU-2025:15293-1
OPENSUSE-SU-2025_1419-1
OPENSUSE-SU-2025_1420-1
OPENSUSE-SU-2025_1432-1
OPENSUSE-SU-2025_1433-1
OPENSUSE-SU-2025_1566-1
RHSA-2025:4441
RHSA-2025:4561
RHSA-2025:4577
RHSA-2025:4607
RHSA-2025:4788
RHSA-2025:4789
RHSA-2025:7429
RHSA-2025:7438
RHSA-2025:7509
RHSA-2025:7538
RHSA-2025:7630
RHSA-2025:7686
RHSA-2025_7429
RHSA-2025_7438
RHSA-2025_7686
SUSE-SU-2025:01942-1
SUSE-SU-2025:02010-1
SUSE-SU-2025:1419-1
SUSE-SU-2025:1420-1
SUSE-SU-2025:1432-1
SUSE-SU-2025:1433-1
SUSE-SU-2025:1566-1
SUSE-SU-2025_01942-1
SUSE-SU-2025_02010-1
SUSE-SU-2025_1419-1
SUSE-SU-2025_1420-1
SUSE-SU-2025_1432-1
SUSE-SU-2025_1433-1
SUSE-SU-2025_1566-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Red Hat
Red Os
Redis
Rocky Linux
Suse