CVE-2025-27151

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.
Configurations

No configuration.

History

29 May 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-29 09:15

Updated : 2025-05-29 14:29


NVD link : CVE-2025-27151

Mitre link : CVE-2025-27151

CVE.ORG link : CVE-2025-27151


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-121

Stack-based Buffer Overflow