CVE-2025-32023 is an out-of-bounds write vulnerability in Redis HyperLogLog operations. In affected Redis versions, an authenticated user can submit a specially crafted string that causes a stack or heap out-of-bounds write. The memory-corruption condition can potentially lead to remote code execution. The issue likely affects Redis versions implementing HyperLogLog operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a Redis exploitation PoC and a full exploit for CVE-2025-32023 centered on malformed HyperLogLog (HLL) encodings. Structure/purpose: - README.md: Claims Redis RCE via MODULE LOAD, but this does not match the actual code. The code targets an HLL parsing/merge memory corruption leading to RCE. - CVE-2025-32023.py (561B): Minimal trigger. Uses redis-py to SET a crafted value with 'HYLL' header and sparse HLL encoding, then calls PFCOUNT on the same key twice to trigger HLL merge logic. The payload uses repeated xzero(0x4000) to induce an integer overflow/size miscalculation ((0x4000*0x20000) -> -0x80000000) consistent with a crash/corruption trigger. - solver-CVE-2025-32023.py (5KB): Full end-to-end RCE exploit. - Creates a valid dense HLL key (hll:dense) and a malformed sparse HLL key (hll:exp) designed to corrupt adjacent heap structures during PFMERGE and sparse-to-dense conversion. - Uses SETRANGE on keys sds:a/sds:b/sds:c to shape heap layout and to corrupt an SDS header (string object metadata), then verifies corruption by checking STRLEN('sds:b') equals a fake 64-bit length. - Sprays many small embstr objects via MSET with a random 8-byte marker, then leaks a large heap region using GETRANGE on the corrupted oversized string. - Egghunts within the leaked heap dump to find a sprayed object and derive a target object address (tadr) and key name (tkey). Then scans for a signature to recover the redis-server base address by matching jemalloc hook pointers (je_ehooks_default_extent_hooks). - Forges a fake Redis object/module-like structure by overwriting object fields via SETRANGE, and builds a ROP chain using gadgets from the local ./redis-server ELF. The chain dup2()s the Redis client socket fd to 0/1/2 and execve('/bin/sh'). - Triggers the corrupted object's free path by issuing 'set {tkey} 0' over the raw TCP connection, then switches to interactive mode to use the shell. Key exploit capabilities: - Remote memory corruption via crafted HLL sparse encoding and PF* commands (PFMERGE/PFCOUNT). - Heap grooming and object type/encoding corruption of Redis string (SDS) metadata. - Arbitrary memory disclosure (heap dump) by inflating string length and reading via GETRANGE. - ASLR bypass by locating redis-server base address from leaked pointers. - ROP-based code execution culminating in an interactive /bin/sh shell over the existing Redis TCP connection. Notable observables: - Redis keys used: hll:exp, hll:dense, sds:a, sds:b, sds:c, sds:_<idx>. - Commands used: SET, SETRANGE, PFADD, PFCOUNT, PFMERGE, MSET, GETRANGE, STRLEN, CLIENT INFO. - Hardcoded target: localhost:6379 (easily adaptable to remote hosts).
This repository contains two Python exploit scripts and a detailed README for CVE-2025-32023, a critical remote code execution (RCE) vulnerability in Redis versions prior to 7.2.4. The vulnerability allows unauthenticated attackers with write access to a Redis instance (typically exposed on TCP port 6379) to execute arbitrary code by manipulating internal data structures via crafted HyperLogLog (HLL) objects. - 'CVE-2025-32023.py' is a minimal proof-of-concept that crafts a malformed HLL object and triggers the vulnerable code path using the Redis Python client. It demonstrates the ability to corrupt memory and potentially trigger the vulnerability. - 'solver-CVE-2025-32023.py' is a full exploit that leverages heap spraying, memory leaks, and a ROP chain to achieve reliable code execution (spawning a shell) on the Redis server. It uses the pwntools library for advanced exploitation and interacts with the Redis server both as a client and via raw socket communication. - The README.md provides a comprehensive overview of the vulnerability, exploitation requirements, impact, mitigation steps, and security recommendations. The exploit targets Redis servers that are exposed to the network without authentication and with write access. The main attack vector is network-based, exploiting the Redis protocol over TCP. The only hardcoded endpoint is 'localhost:6379', but in real-world attacks, this would be replaced with the target server's address. The exploit is operational and demonstrates a full RCE chain, making it highly impactful if used against vulnerable Redis deployments.
This repository contains a working exploit and proof-of-concept (PoC) for CVE-2025-32023, a critical vulnerability in Redis (versions >=2.8 and before 8.0.3, 7.4.5, 7.2.10, 6.2.19). The vulnerability is due to an integer overflow in the HyperLogLog (HLL) sparse encoding logic, which allows an attacker to perform out-of-bounds writes on the stack or heap. The exploit consists of two Python scripts: - `poc.py`: A minimal PoC that crafts a malformed HLL object and triggers the vulnerable code path using standard Redis commands. - `solver-<hash>.py`: A full exploit that leverages the vulnerability to corrupt heap objects, spray memory with controlled data, leak heap addresses, construct a fake module object, and ultimately execute a ROP chain to spawn a shell on the Redis server. The exploit uses the `pwn` library for advanced memory manipulation and ROP chain construction. The exploit requires access to a vulnerable Redis instance (default: localhost:6379) and does not require authentication or special configuration beyond the vulnerable version. The README provides a detailed technical explanation of the bug, affected versions, and exploitation strategy. The main attack vector is network-based, targeting the Redis TCP service. The exploit demonstrates a high level of technical maturity, achieving reliable remote code execution via heap and stack manipulation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.