CVE-2025-62507 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigge…
High CVSS: 7.7

CVE-2025-62507

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer overflow, which may potentially lead to remote code execution. This issue is fixed in version 8.2.3. To workaround this issue without patching the redis-server executable is to prevent users from executing XACKDEL operation. This can be done using ACL to restrict XACKDEL command.
Vendor
Redis
Product
Redis
CWE
CWE-20
Yayın Tarihi
2025-11-04 22:16:38
Güncelleme
2025-12-08 16:23:27
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar