-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Binary: redis Architecture: all Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Aron Xu Description: redis - Persistent key-value database with network interface (metapackage Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: fcb75c8fadcfe8a00fde545fb69f7e16e36c5adc 6604 redis_8.0.2-3+deb13u3_all-buildd.buildinfo b2ab098e0053e404b17e23effdcda47845db4cd1 18072 redis_8.0.2-3+deb13u3_all.deb Checksums-Sha256: f704408aa2053ba8b2d04befa5f972ba7f2cbc76c2c4aee8323d91f5a5f21d3c 6604 redis_8.0.2-3+deb13u3_all-buildd.buildinfo 219b918db06b4f2c41435a224c3cdb45d3fcff9a72466a3a789a3c6bd7e2741e 18072 redis_8.0.2-3+deb13u3_all.deb Files: a92b5019deb411a793c6e7ba2324da22 6604 database optional redis_8.0.2-3+deb13u3_all-buildd.buildinfo ca25c3175f0cda2f6370889069250656 18072 database optional redis_8.0.2-3+deb13u3_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmq85csACgkQmgPNRvTf /zdYIhAAswlg4DC4fI/B6vHDSnBlx6IpyJ7po2f5Zp4zui4YLRqgSdfBRgcZoa4n YvBwR2NOh4vaMLV8AUe6RvD1dFSg8NeBcz2uFfPWQmJ6zVWtDpjVMf8u+vWHKyMN ktg7ZzIgk8LYFH1OU6b3WB3WmRazTdqfzKsL2yzq2OfgRBKTfAuoqHHVIa6OFjxu ij0qdrPRxnGTMeMF2buI7s9ruOFpHY+hobLxZ5dgVAlUPSDGphAg7rw1QclauGrG Ssg0vUzugE9jFoZCi0MzuEnOxmItKFEaUR9o9Pjy6C5Y02Ed9xbeGw+sBO+1XkrE xB4qSoQfNi2ogZT7BcpcdEZMkMr8vo8L51RSPzmphP5CyX2ZPqhSgzAVHWuGE6Uh +7x58lYTa1E3ZfCTZtJvxv2n2LDlCdo+7ZoapS3aJ7783PMMd5G6BT81d7Oc5iXB SOpd7EDo/Ijyf8VW+iBK1fmXZ7dMUHuKx8/+Ol4HrjUznT2KmBWTN5s/R0+4+edY aGdoJDnBKcUQT6mRSsz0KJF8Wys4mL5IcEYPYOkvAXaec8jhjbvanM//rIHYYYKe 6SBLYF1iCSfGzmjlbJo5wwRUP+negRQY4Bfd/vTB2PMHhdHMP+75REBWjze+eC+D wejdx+KJaWfOv53H32EaWMsdPk6U3kGAB90LIJpyDDD05n+PoUE= =093u -----END PGP SIGNATURE-----