CVE-2025-46817
Publication date 3 October 2025
Last updated 26 November 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| redict | 25.10 questing |
Needs evaluation
|
| 25.04 plucky |
Needs evaluation
|
|
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| valkey | 25.10 questing |
Fixed 8.1.4+dfsg1-0ubuntu0.2
|
| 25.04 plucky |
Fixed 8.0.6+dfsg1-0ubuntu0.2
|
|
| 24.04 LTS noble |
Fixed 7.2.11+dfsg1-0ubuntu0.2
|
|
| 22.04 LTS jammy | Not in release | |
| redis | 25.10 questing |
Not affected
|
| 25.04 plucky |
Not affected
|
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | High |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity impact | High |
| Availability impact | High |
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-7893-1
- Valkey vulnerabilities
- 26 November 2025
Other references
- https://www.cve.org/CVERecord?id=CVE-2025-46817
- https://github.com/redis/redis/security/advisories/GHSA-m8fj-85cg-7vhp
- https://github.com/redis/redis/commit/fc9abc775e308374f667fdf3e723ef4b7eb0e3ca (8.2.2)
- https://github.com/valkey-io/valkey/commit/6dd003e88feace83e55491f32376f6927896e31e
- https://github.com/redis/redis/commit/fc9abc775e308374f667fdf3e723ef4b7eb0e3ca
- https://github.com/redis/redis/releases/tag/8.2.2