CVE-2025-27151
redis-check-aof may lead to stack overflow and potential RCE
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.
A flaw was found in Redis. Using memcpy with the strlen filepath when copying a user-supplied file path into a fixed-size stack buffer in redis-check-aof results in a stack-based buffer overflow. This flaw allows a local attacker to trigger the overflow by providing a specially crafted file path, allowing potential code execution. The primary consequence is a possible denial of service.
Several security issues were discovered in Redis, a persistent key-value database, which could result in the execution of arbitrary code or denial of service. For the stable distribution (bookworm), these problems have been fixed in version 5:7.0.15-1~deb12u5.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-02-19 CVE Reserved
- 2025-05-29 CVE Published
- 2025-05-29 CVE Updated
- 2025-08-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-121: Stack-based Buffer Overflow
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/redis/redis/security/advisories/GHSA-5453-q98w-cmvm | X_refsource_confirm | |
https://github.com/redis/redis/commit/643b5db235cb82508e72f11c7b4bbfc7dc39be56 | X_refsource_misc | |
https://github.com/redis/redis/releases/tag/8.0.2 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2025-27151 | 2025-07-28 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2369153 | 2025-07-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redis Search vendor "Redis" | Redis Search vendor "Redis" for product "Redis" | >= 7.0.0 < 8.0.2 Search vendor "Redis" for product "Redis" and version " >= 7.0.0 < 8.0.2" | en |
Affected
|