[Git][security-tracker-team/security-tracker][master] Add CVE-2025-48367/{redict,redis,valkey}
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 8 07:39:42 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0966c8ab by Salvatore Bonaccorso at 2025-07-08T08:39:28+02:00
Add CVE-2025-48367/{redict,redis,valkey}
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -172,7 +172,14 @@ CVE-2025-52492 (A vulnerability has been discovered in the firmware of Paxton Pa
CVE-2025-4779 (lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cro ...)
NOT-FOR-US: lunary-ai/lunary
CVE-2025-48367 (Redis is an open source, in-memory database that persists on disk. An ...)
- TODO: check
+ - redict <unfixed>
+ - redis <unfixed>
+ - valkey <unfixed>
+ NOTE: https://codeberg.org/redict/redict/issues/105
+ NOTE: https://github.com/redis/redis/security/advisories/GHSA-4q32-c38c-pwgq
+ NOTE: Fixed by: https://github.com/redis/redis/commit/bde62951accfc4bb0a516276fd0b4b307e140ce2 (8.0.3)
+ NOTE: https://github.com/valkey-io/valkey/pull/2315
+ NOTE: Fixed by: https://github.com/valkey-io/valkey/commit/cb10d9d78f35945b667e46967b3980e89954d73b
CVE-2025-47202 (In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exyn ...)
NOT-FOR-US: Samsung
CVE-2025-45479 (Insufficient security mechanisms for created containers in educoder ch ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0966c8abc4bbbdeb31328e3c4449584862ae1140
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0966c8abc4bbbdeb31328e3c4449584862ae1140
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250708/d02bcb78/attachment.htm>
More information about the debian-security-tracker-commits
mailing list