Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 954265 (CVE-2025-21605) - <dev-db/redict-7.3.3 <dev-db/redis-{6.2.18,7.2.8,7.4.3}: An unauthenticated client can cause an unlimited growth of output buffers
Summary: <dev-db/redict-7.3.3 <dev-db/redis-{6.2.18,7.2.8,7.4.3}: An unauthenticated c...
Status: CONFIRMED
Alias: CVE-2025-21605
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: B3 [stable]
Keywords:
Depends on: 955616
Blocks:
  Show dependency tree
 
Reported: 2025-04-23 12:59 UTC by Petr Vaněk
Modified: 2025-05-29 06:39 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Petr Vaněk gentoo-dev 2025-04-23 12:59:57 UTC
(CVE-2025-21605) An unauthenticated client can cause an unlimited growth of output buffers
Comment 1 Larry the Git Cow gentoo-dev 2025-04-23 13:26:11 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=934e248a9e5f1cc9cdd63e7b9a3a48b5fe71d815

commit 934e248a9e5f1cc9cdd63e7b9a3a48b5fe71d815
Author:     Petr Vaněk <arkamar@gentoo.org>
AuthorDate: 2025-04-23 13:15:12 +0000
Commit:     Petr Vaněk <arkamar@gentoo.org>
CommitDate: 2025-04-23 13:25:44 +0000

    dev-db/redis: add 7.4.3
    
    Bug: https://bugs.gentoo.org/954265
    Signed-off-by: Petr Vaněk <arkamar@gentoo.org>

 dev-db/redis/Manifest           |   1 +
 dev-db/redis/redis-7.4.3.ebuild | 196 ++++++++++++++++++++++++++++++++++++++++
 2 files changed, 197 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b0b27885c7232595c6ab4f378085b44fecc24cad

commit b0b27885c7232595c6ab4f378085b44fecc24cad
Author:     Petr Vaněk <arkamar@gentoo.org>
AuthorDate: 2025-04-23 13:09:58 +0000
Commit:     Petr Vaněk <arkamar@gentoo.org>
CommitDate: 2025-04-23 13:25:43 +0000

    dev-db/redis: add 7.2.8
    
    Bug: https://bugs.gentoo.org/954265
    Signed-off-by: Petr Vaněk <arkamar@gentoo.org>

 dev-db/redis/Manifest           |   1 +
 dev-db/redis/redis-7.2.8.ebuild | 200 ++++++++++++++++++++++++++++++++++++++++
 2 files changed, 201 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=13f514607861ce149246dad9fe817cbec29a855b

commit 13f514607861ce149246dad9fe817cbec29a855b
Author:     Petr Vaněk <arkamar@gentoo.org>
AuthorDate: 2025-04-23 13:02:26 +0000
Commit:     Petr Vaněk <arkamar@gentoo.org>
CommitDate: 2025-04-23 13:25:42 +0000

    dev-db/redis: add 6.2.18
    
    Bug: https://bugs.gentoo.org/954265
    Signed-off-by: Petr Vaněk <arkamar@gentoo.org>

 dev-db/redis/Manifest            |   1 +
 dev-db/redis/redis-6.2.18.ebuild | 195 +++++++++++++++++++++++++++++++++++++++
 2 files changed, 196 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2025-05-29 06:25:33 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=3081b33e9da00a1cd6c7777b5c32ee2e366dfb48

commit 3081b33e9da00a1cd6c7777b5c32ee2e366dfb48
Author:     Haelwenn (lanodan) Monnier <contact@hacktivis.me>
AuthorDate: 2025-05-29 01:44:49 +0000
Commit:     Petr Vaněk <arkamar@gentoo.org>
CommitDate: 2025-05-29 06:24:10 +0000

    dev-db/redict: drop 7.3.2
    
    Signed-off-by: Haelwenn (lanodan) Monnier <contact@hacktivis.me>
    Bug: https://bugs.gentoo.org/954265
    Part-of: https://github.com/gentoo/gentoo/pull/42315
    Closes: https://github.com/gentoo/gentoo/pull/42315
    Signed-off-by: Petr Vaněk <arkamar@gentoo.org>

 dev-db/redict/Manifest            |   1 -
 dev-db/redict/redict-7.3.2.ebuild | 160 --------------------------------------
 2 files changed, 161 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5ab948a0fd8c9da34e9c4da5139a292355d94880

commit 5ab948a0fd8c9da34e9c4da5139a292355d94880
Author:     Haelwenn (lanodan) Monnier <contact@hacktivis.me>
AuthorDate: 2025-05-29 01:38:49 +0000
Commit:     Petr Vaněk <arkamar@gentoo.org>
CommitDate: 2025-05-29 06:24:09 +0000

    dev-db/redict: add 7.3.3
    
    Fixes CVE-2025-21605
    
    Signed-off-by: Haelwenn (lanodan) Monnier <contact@hacktivis.me>
    Bug: https://bugs.gentoo.org/954265
    Part-of: https://github.com/gentoo/gentoo/pull/42315
    Signed-off-by: Petr Vaněk <arkamar@gentoo.org>

 dev-db/redict/Manifest            |   1 +
 dev-db/redict/redict-7.3.3.ebuild | 160 ++++++++++++++++++++++++++++++++++++++
 2 files changed, 161 insertions(+)