Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities Ubuntu Security

USN-8120-1: Redis vulnerability

A memory handling flaw in Redis during hyperloglog operations (CVE-2025-32023, CVSS 7.0 HIGH) can be exploited via specially crafted network traffic to cause a denial of service or achieve remote code execution. The vulnerability affects Redis versions 2.8.0 through 6.2.18, 7.2.0 through 7.2.9, 7.4.0 through 7.4.4, and 8.0.0 through 8.0.2. Remediation requires upgrading to Redis 6.2.19, 7.2.10, 7.4.5, or 8.0.3, followed by a service restart.
Read Full Article →

Ubuntu Security Notices USN-8120-1 USN-8120-1: Redis vulnerability Publication date 24 March 2026 Overview Redis could be made to crash or run programs if it received specially crafted network traffic. Releases 24.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages redis - Persistent key-value database with network interface Details Seunghyun Lee discovered that Redis incorrectly handled memory during hyperloglog operations. An attacker could use this issue to cause a denial of service, or possibly achieve remote code execution. Seunghyun Lee discovered that Redis incorrectly handled memory during hyperloglog operations. An attacker could use this issue to cause a denial of service, or possibly achieve remote code execution. Update instructions After a standard system update you need to restart redis to make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 24.04 LTS noble redis – 5:7.0.15-1ubuntu0.24.04.3 redis-server – 5:7.0.15-1ubuntu0.24.04.3 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2025-32023 CVE-2025-32023

Share this article