MGASA-2025-0033 - Updated redis packages fix security vulnerabilities

Publication date: 03 Feb 2025
URL: https://advisories.mageia.org/MGASA-2025-0033.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-46981,
     CVE-2024-51741

Redis' Lua library commands may lead to remote code execution.
(CVE-2024-46981)
Redis allows denial-of-service due to malformed ACL selectors.
(CVE-2024-51741)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33924
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4HQU52SRIF5TB4GL3LJOHKX2MUHXNHH6/
- https://lists.debian.org/debian-security-announce/2025/msg00018.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-46981
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-51741

SRPMS:
- 9/core/redis-7.0.14-1.2.mga9

Mageia 2025-0033: redis Security Advisory Updates

Redis' Lua library commands may lead to remote code execution

Summary

Redis' Lua library commands may lead to remote code execution. (CVE-2024-46981) Redis allows denial-of-service due to malformed ACL selectors. (CVE-2024-51741)

References

- https://bugs.mageia.org/show_bug.cgi?id=33924

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4HQU52SRIF5TB4GL3LJOHKX2MUHXNHH6/

- https://lists.debian.org/debian-security-announce/2025/msg00018.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-46981

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-51741

Resolution

MGASA-2025-0033 - Updated redis packages fix security vulnerabilities

SRPMS

- 9/core/redis-7.0.14-1.2.mga9

Severity
Publication date: 03 Feb 2025
URL: https://advisories.mageia.org/MGASA-2025-0033.html
Type: security
CVE: CVE-2024-46981, CVE-2024-51741

Related News