Vulnerabilities

Redis on Linux: which version fixes what

Redis has a respectable advisory list, and almost every Redis server that gets compromised is compromised through configuration rather than through any of them.

SecAI tracks 75 distinct CVEs affecting Redis across the 6 distributions below, of which 20 have no fixed package version on at least one of them. Each row names the package version that fixes it on that release.

What it is, and why it is on your server

Redis is an in-memory data store used for caching, sessions and queues. It is fast because it does very little, and historically that included doing very little about authentication.

Why its advisories behave the way they do

  • An open Redis is a remote shell. With no password and no bind address, an attacker can write arbitrary files as the Redis user, which has been turned into an SSH key in authorized_keys and a cron job more times than any CVE on this list.
  • It is usually installed as a dependency. Somebody adds a caching plugin, Redis arrives with it, and nobody treats it as a service with a configuration.
  • Lua sandbox escapes are the interesting CVEs. Several advisories are about breaking out of the embedded scripting engine, which matters if anything untrusted can run a script.

Check what you are actually running

The version that matters is the package version, not the upstream one. Distributions backport security fixes without changing the number before the dash, so a release that looks years old is frequently fully patched, and the revision after the dash is the only part that tells you.

Debian and Ubuntu
dpkg-query -W -f='${Package} ${Version}\n' redis-server redis-tools 2>/dev/null
Rocky Linux and AlmaLinux
rpm -q redis

The first check is not the version. `ss -lntp | grep 6379` and `grep -E "^(bind|requirepass|protected-mode)" /etc/redis/redis.conf` will tell you more about your exposure than any advisory list.

Fixed versions, per distribution

Each distribution patches on its own schedule and under its own version scheme, so the same CVE has a different answer on each of them. These come from the distributions’ own advisory data, asked per release. Where a release has no fixed version, that is what the advisory says, not a gap in the data.

Ubuntu 22.04 LTSsource package: redis

CVEPublishedFixed in package version
CVE-2025-498442025-10-165:6.0.16-1ubuntu1.1
CVE-2021-312942023-07-15no fixed version released

Showing the 2 most recent of 2 that apply to Ubuntu 22.04 LTS, 1 of which have no fixed version released.

Ubuntu 24.04 LTSsource package: redis

CVEPublishedFixed in package version
CVE-2026-929252026-09-17no fixed version released
CVE-2026-819342026-08-27no fixed version released
CVE-2026-663732026-07-25no fixed version released
CVE-2026-234792026-05-05no fixed version released
CVE-2026-236312026-05-05no fixed version released
CVE-2026-252432026-05-05no fixed version released
CVE-2026-255882026-05-05no fixed version released
CVE-2026-255892026-05-05no fixed version released
CVE-2025-320232026-03-245:7.0.15-1ubuntu0.24.04.3
CVE-2025-498442025-10-155:7.0.15-1ubuntu0.24.04.2
CVE-2025-468182025-10-03no fixed version released
CVE-2025-468192025-10-03no fixed version released
CVE-2025-466862025-07-23no fixed version released
CVE-2025-483672025-07-07no fixed version released
CVE-2025-491122025-06-02no fixed version released
CVE-2025-271512025-05-29no fixed version released
CVE-2025-216052025-04-23no fixed version released
CVE-2024-312282025-03-055:7.0.15-1ubuntu0.24.04.1
CVE-2024-469812025-03-055:7.0.15-1ubuntu0.24.04.1
CVE-2024-517412025-03-055:7.0.15-1ubuntu0.24.04.1
CVE-2024-312272024-10-07no fixed version released
CVE-2024-314492024-10-075:7.0.15-1ubuntu0.24.04.4
CVE-2023-316552023-05-18no fixed version released

Showing the 23 most recent of 23 that apply to Ubuntu 24.04 LTS, 17 of which have no fixed version released.

Debian 12 (bookworm)source package: redis

CVEPublishedFixed in package version
CVE-2026-929252026-09-175:7.0.15-1~deb12u10
CVE-2026-819342026-08-275:7.0.15-1~deb12u10
CVE-2026-663732026-07-255:7.0.15-1~deb12u9
CVE-2026-236312026-05-055:7.0.15-1~deb12u8
CVE-2026-252432026-05-055:7.0.15-1~deb12u8
CVE-2025-677332026-02-235:7.0.15-1~deb12u7
CVE-2026-218632026-02-235:7.0.15-1~deb12u7
CVE-2025-468172025-10-085:7.0.15-1~deb12u6
CVE-2025-468182025-10-085:7.0.15-1~deb12u6
CVE-2025-468192025-10-085:7.0.15-1~deb12u6
CVE-2025-498442025-10-085:7.0.15-1~deb12u6
CVE-2025-271512025-07-315:7.0.15-1~deb12u5
CVE-2025-320232025-07-315:7.0.15-1~deb12u5
CVE-2025-483672025-07-315:7.0.15-1~deb12u5
CVE-2025-466862025-07-23no fixed version released
CVE-2025-491122025-06-02no fixed version released
CVE-2025-216052025-04-235:7.0.15-1~deb12u4
CVE-2024-469812025-01-305:7.0.15-1~deb12u3
CVE-2024-517412025-01-305:7.0.15-1~deb12u3
CVE-2024-312272024-10-075:7.0.15-1~deb12u2
CVE-2024-312282024-10-075:7.0.15-1~deb12u2
CVE-2024-314492024-10-075:7.0.15-1~deb12u2
CVE-2022-248342024-01-295:7.0.15-1~deb12u1
CVE-2023-368242024-01-295:7.0.15-1~deb12u1
CVE-2023-410532024-01-295:7.0.15-1~deb12u1

Showing the 25 most recent of 70 that apply to Debian 12 (bookworm), 4 of which have no fixed version released.

Debian 13 (trixie)source package: redis

CVEPublishedFixed in package version
CVE-2026-929252026-09-17no fixed version released
CVE-2026-819342026-08-27no fixed version released
CVE-2026-234792026-05-05no fixed version released
CVE-2026-236312026-05-05no fixed version released
CVE-2026-252432026-05-05no fixed version released
CVE-2025-677332026-02-235:8.0.2-3+deb13u2
CVE-2026-218632026-02-235:8.0.2-3+deb13u2
CVE-2025-468172025-10-085:8.0.2-3+deb13u1
CVE-2025-468182025-10-085:8.0.2-3+deb13u1
CVE-2025-468192025-10-085:8.0.2-3+deb13u1
CVE-2025-498442025-10-085:8.0.2-3+deb13u1
CVE-2025-466862025-07-23no fixed version released
CVE-2025-320232025-07-075:8.0.2-2
CVE-2025-483672025-07-075:8.0.2-2
CVE-2025-491122025-06-02no fixed version released
CVE-2025-271512025-05-295:8.0.2-2
CVE-2025-216052025-04-235:7.0.15-3.1
CVE-2024-469812025-01-065:7.0.15-3
CVE-2024-517412025-01-065:7.0.15-3
CVE-2024-312272024-10-075:7.0.15-2
CVE-2024-312282024-10-075:7.0.15-2
CVE-2024-314492024-10-075:7.0.15-2
CVE-2023-410562024-01-105:7.0.15-1
CVE-2023-451452023-10-185:7.0.14-1
CVE-2023-410532023-09-065:7.0.13-1

Showing the 25 most recent of 70 that apply to Debian 13 (trixie), 9 of which have no fixed version released.

Rocky Linux 9source package: redis

CVEPublishedFixed in package version
CVE-2026-663732026-09-090:6.2.24-1.el9_8
CVE-2026-819342026-09-090:6.2.24-1.el9_8
CVE-2026-725682026-09-090:7.2.16-1.module+el9.8.0+40315+e15874a8
CVE-2026-234792026-06-130:7.2.14-1.module+el9.8.0+40207+e2014501
CVE-2026-236312026-06-130:7.2.14-1.module+el9.8.0+40207+e2014501
CVE-2026-252432026-06-130:7.2.14-1.module+el9.8.0+40207+e2014501
CVE-2025-468172025-11-290:7.2.11-1.module+el9.7.0+40013+17379f63
CVE-2025-468182025-11-290:7.2.11-1.module+el9.7.0+40013+17379f63
CVE-2025-468192025-11-290:7.2.11-1.module+el9.7.0+40013+17379f63
CVE-2025-498442025-11-290:7.2.11-1.module+el9.7.0+40013+17379f63
CVE-2025-320232025-10-040:6.2.19-1.el9_6
CVE-2025-483672025-10-040:6.2.19-1.el9_6
CVE-2025-271512025-10-040:7.2.10-1.module+el9.6.0+32323+e27e860a
CVE-2025-216052025-10-040:7.2.8-1.module+el9.6.0+32036+eb8f79e6
CVE-2024-469812025-03-170:7.2.7-1.module+el9.5.0+30204+5d6debe1
CVE-2024-517412025-03-170:7.2.7-1.module+el9.5.0+30204+5d6debe1
CVE-2022-248342025-03-170:6.2.17-1.el9_5
CVE-2023-451452025-03-170:6.2.17-1.el9_5
CVE-2024-312282025-03-170:6.2.17-1.el9_5
CVE-2024-314492025-03-170:6.2.17-1.el9_5
CVE-2022-247352022-11-150:6.2.7-1.el9
CVE-2022-247362022-11-150:6.2.7-1.el9

Showing the 22 most recent of 22 that apply to Rocky Linux 9.

AlmaLinux 9source package: redis

CVEPublishedFixed in package version
CVE-2026-663732026-09-086.2.24-1.el9_8
CVE-2026-819342026-09-086.2.24-1.el9_8
CVE-2026-234792026-06-117.2.14-1.module_el9.8.0+258+b8f945d3
CVE-2026-236312026-06-117.2.14-1.module_el9.8.0+258+b8f945d3
CVE-2026-252432026-06-117.2.14-1.module_el9.8.0+258+b8f945d3
CVE-2025-468172025-11-116.2.20-2.el9_7
CVE-2025-468182025-11-116.2.20-2.el9_7
CVE-2025-468192025-11-116.2.20-2.el9_7
CVE-2025-498442025-11-116.2.20-2.el9_7
CVE-2025-271512025-07-287.2.10-1.module_el9.6.0+173+efaf9205
CVE-2025-320232025-07-287.2.10-1.module_el9.6.0+173+efaf9205
CVE-2025-483672025-07-287.2.10-1.module_el9.6.0+173+efaf9205
CVE-2025-216052025-05-137.2.8-1.module_el9.6.0+168+b8d8e900
CVE-2024-469812025-01-277.2.7-1.module_el9.5.0+134+2e645600
CVE-2024-517412025-01-277.2.7-1.module_el9.5.0+134+2e645600
CVE-2022-248342025-01-276.2.17-1.el9_5
CVE-2023-451452025-01-276.2.17-1.el9_5
CVE-2024-312282025-01-276.2.17-1.el9_5
CVE-2024-314492025-01-276.2.17-1.el9_5
CVE-2023-410532024-12-057.2.6-1.module_el9.5.0+130+36ae7635
CVE-2024-312272024-12-057.2.6-1.module_el9.5.0+130+36ae7635
CVE-2022-247352022-11-156.2.7-1.el9
CVE-2022-247362022-11-156.2.7-1.el9

Showing the 23 most recent of 23 that apply to AlmaLinux 9.

Advisory data last refreshed 26 September 2026. It is re-read daily.

What this page does not tell you

It does not tell you whether your server is affected. A CVE applying to a package is not the same as a CVE applying to your installation: the fix may already be backported into what you are running, the vulnerable module may not be loaded, or the service may not be reachable from anywhere that matters. Answering that needs the versions on your machine, not a list.

It also carries no count of how many servers are affected. SecAI monitors a small fleet, and a percentage drawn from it would be arithmetic on a sample too small to mean anything. When that changes, the number will appear here and the page will say when it started.

Read next

Find out which of these you are running

One read-only command, no account, no agent. It reads the installed package versions on your server and tells you which advisories actually apply to them, Redis included. It changes nothing.