UBUNTU-CVE-2025-21605

Source
https://ubuntu.com/security/CVE-2025-21605
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-21605.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-21605
Related
Published
2025-04-23T16:15:00Z
Modified
2025-04-30T16:30:25Z
Summary
[none]
Details

Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can cause unlimited growth of output buffers, until the server runs out of memory or is killed. By default, the Redis configuration does not limit the output buffer of normal clients (see client-output-buffer-limit). Therefore, the output buffer can grow unlimitedly over time. As a result, the service is exhausted and the memory is unavailable. When password authentication is enabled on the Redis server, but no password is provided, the client can still cause the output buffer to grow from "NOAUTH" responses until the system will run out of memory. This issue has been patched in version 7.4.3. An additional workaround to mitigate this problem without patching the redis-server executable is to block access to prevent unauthenticated users from connecting to Redis. This can be done in different ways. Either using network access control tools like firewalls, iptables, security groups, etc, or enabling TLS and requiring users to authenticate using client side certificates.

References

Affected packages

Ubuntu:Pro:14.04:LTS / redis

Package

Name
redis
Purl
pkg:deb/ubuntu/redis@2:2.8.4-2ubuntu0.2+esm4?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:2.*

2:2.6.13-1
2:2.6.16-3
2:2.8.0-1
2:2.8.2-1
2:2.8.4-2
2:2.8.4-2ubuntu0.2
2:2.8.4-2ubuntu0.2+esm1
2:2.8.4-2ubuntu0.2+esm2
2:2.8.4-2ubuntu0.2+esm3
2:2.8.4-2ubuntu0.2+esm4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / redis

Package

Name
redis
Purl
pkg:deb/ubuntu/redis@2:3.0.6-1ubuntu0.4+esm3?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:3.*

2:3.0.3-3
2:3.0.5-1
2:3.0.5-2
2:3.0.5-3
2:3.0.5-4
2:3.0.6-1
2:3.0.6-1ubuntu0.2
2:3.0.6-1ubuntu0.3
2:3.0.6-1ubuntu0.4
2:3.0.6-1ubuntu0.4+esm1
2:3.0.6-1ubuntu0.4+esm2
2:3.0.6-1ubuntu0.4+esm3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / redis

Package

Name
redis
Purl
pkg:deb/ubuntu/redis@5:4.0.9-1ubuntu0.2+esm5?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:4.*

4:4.0.1-7
4:4.0.2-6
4:4.0.2-9

5:4.*

5:4.0.5-1
5:4.0.6-1
5:4.0.6-2
5:4.0.7-1
5:4.0.8-1
5:4.0.8-2
5:4.0.9-1
5:4.0.9-1ubuntu0.1
5:4.0.9-1ubuntu0.2
5:4.0.9-1ubuntu0.2+esm2
5:4.0.9-1ubuntu0.2+esm3
5:4.0.9-1ubuntu0.2+esm4
5:4.0.9-1ubuntu0.2+esm5

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / redis

Package

Name
redis
Purl
pkg:deb/ubuntu/redis@5:5.0.7-2ubuntu0.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5:5.*

5:5.0.5-2build1
5:5.0.6-1
5:5.0.7-1
5:5.0.7-2
5:5.0.7-2ubuntu0.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / redis

Package

Name
redis
Purl
pkg:deb/ubuntu/redis@5:6.0.16-1ubuntu1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5:6.*

5:6.0.15-1
5:6.0.16-1
5:6.0.16-1build1
5:6.0.16-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / redict

Package

Name
redict
Purl
pkg:deb/ubuntu/redict@7.3.0+ds-3?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.3.0+ds-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / redis

Package

Name
redis
Purl
pkg:deb/ubuntu/redis@5:7.0.15-1ubuntu0.24.10.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5:7.*

5:7.0.15-1build2
5:7.0.15-1ubuntu0.24.10.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / valkey

Package

Name
valkey
Purl
pkg:deb/ubuntu/valkey@7.2.8+dfsg1-0ubuntu0.24.10.2?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.2.5+dfsg1-2ubuntu1
7.2.5+dfsg1-2ubuntu2
7.2.5+dfsg1-2ubuntu3
7.2.5+dfsg1-2ubuntu4
7.2.7+dfsg1-0ubuntu0.24.10.1
7.2.8+dfsg1-0ubuntu0.24.10.1
7.2.8+dfsg1-0ubuntu0.24.10.2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / redis

Package

Name
redis
Purl
pkg:deb/ubuntu/redis@5:7.0.15-1ubuntu0.24.04.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5:7.*

5:7.0.12-1
5:7.0.14-1
5:7.0.14-2
5:7.0.15-1
5:7.0.15-1build1
5:7.0.15-1build2
5:7.0.15-1ubuntu0.24.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / valkey

Package

Name
valkey
Purl
pkg:deb/ubuntu/valkey@7.2.8+dfsg1-0ubuntu0.24.04.2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.2.5+dfsg1-2ubuntu4~24.04.1
7.2.7+dfsg1-0ubuntu0.24.04.1
7.2.8+dfsg1-0ubuntu0.24.04.1
7.2.8+dfsg1-0ubuntu0.24.04.2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:25.04 / redict

Package

Name
redict
Purl
pkg:deb/ubuntu/redict@7.3.2+ds-1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.3.0+ds-3
7.3.1+ds-1
7.3.2+ds-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:25.04 / redis

Package

Name
redis
Purl
pkg:deb/ubuntu/redis@5:7.0.15-3?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5:7.*

5:7.0.15-1build2
5:7.0.15-2
5:7.0.15-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:25.04 / valkey

Package

Name
valkey
Purl
pkg:deb/ubuntu/valkey@8.0.2+dfsg1-1ubuntu1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.2.5+dfsg1-2ubuntu4

8.*

8.0.1+dfsg1-1ubuntu1
8.0.2+dfsg1-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}