CODERED VTA

Debian Patches Multiple Redis Flaws Allowing Denial of Service and Arbitrary Code Execution

Medium
Analytics dashboard on screen
Photo by Luke Chesser on Unsplash

Debian has issued security update DSA-6538-1 for Redis, the persistent key value database that underpins caching, session storage and message queues in many application stacks. The advisory covers multiple vulnerabilities that could result in denial of service or arbitrary code execution. It also includes CVE-2026-66373, which addresses an incomplete fix for CVE-2026-25243; because that interim fix was never released on its own in Debian stable, only the comprehensive fix is shipped. Any Debian stable system running the redis packages is in scope.

The update also resolves related defects that were never assigned CVE identifiers. ACL key permission checks could be bypassed for the SORT, GEORADIUS, GEORADIUSBYMEMBER, XREAD and XREADGROUP commands, letting a restricted client reach keys its ruleset should have denied. The maintainers also fixed an out of bounds read during ACL key extraction for KEYNUM commands invoked with the wrong arity, a use after free in the blocked client list, another out of bounds read in HGETEX, and an integer overflow in the HyperLogLog hash function. Missing validation of slot information when loading RDB files was corrected as well. Debian has not published exploitation details or proof of concept code.

Redis frequently sits deep inside trusted infrastructure, holding session tokens, queues and cached records, so an ACL bypass or memory corruption there reaches data perimeter controls assume is protected. Current exploitation probability is modest: FIRST EPSS puts CVE-2026-66373 at 0.9 percent and CVE-2026-25243 at 3.7 percent over the next thirty days. Unpatched hosts remain exposed whatever those thirty day figures suggest.

Attack Surface

Database, Server OS, Infrastructure

Tactics

Initial Access, Execution, Privilege Escalation, Impact

Techniques

  • T1190 – Exploit Public-Facing Application
  • T1068 – Exploitation for Privilege Escalation
  • T1499 – Endpoint Denial of Service
  • T1499.004 – Application or System Exploitation

SuperPRO's Threat Countermeasures Procedures

  1. Apply DSA-6538-1 on Debian stable with apt update && apt install –only-upgrade redis-server redis-tools; this build carries the comprehensive fix covering both CVE-2026-66373 and the earlier CVE-2026-25243.
  2. Check with apt policy redis-server that the candidate package resolves to the DSA-6538-1 build for Debian stable, since that build is the only one carrying the comprehensive fix for both CVE-2026-66373 and the earlier CVE-2026-25243.
  3. Ensure the Debian stable security suite entry for security.debian.org is present in /etc/apt/sources.list so the DSA-6538-1 redis packages are actually offered to the host before the upgrade is attempted.
  4. Until the patched package is deployed, do not treat Redis ACLs as a security boundary for SORT, GEORADIUS, GEORADIUSBYMEMBER, XREAD and XREADGROUP; enumerate current rules with ACL LIST and remove unneeded restricted users.
  5. Treat RDB files as untrusted input given the missing slot validation during RDB load: restrict write permissions on the configured dir and dbfilename paths to the redis user only, and never load a dump.rdb sourced from outside your own backup chain.
  6. Note that several defects fixed in DSA-6538-1, including the ACL key permission bypass and the HyperLogLog integer overflow, were never assigned CVE identifiers, so scanning only for CVE-2026-66373 and CVE-2026-25243 understates exposure; validate against the fixed redis package version instead.
  7. Record the fixed redis package version listed on the Debian security tracker entry for DSA-6538-1 in your patch baseline and scan estate-wide with dpkg -l redis-server to find hosts still on the vulnerable build.

Source

Code Red Cyber / VTA – coderedcyber.ai