Name
CVE-2025-27151
Description
Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.
CWEs
Published Date
Updated Date
Workaround
-
Analysis#
Vulnerability Ratings#
4.7
CVSSv31
9.8
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
redis (yocto:scarthgap)
#
Title
Author
Resolve
1
Check length of AOF file name in redis-check-aof
YaacovHazan <yaacov.hazan@redis.com>
CVE-2025-27151
redis (yocto:scarthgap)
#
Title
Author
Resolve
1
Check length of AOF file name in redis-check-aof
YaacovHazan <yaacov.hazan@redis.com>
CVE-2025-27151