-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym Architecture: armhf Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: armhf Build Daemon (arm-conova-02) Changed-By: Aron Xu Description: redis-sentinel - Persistent key-value database with network interface (monitoring) redis-server - Persistent key-value database with network interface redis-tools - Persistent key-value database with network interface (client) Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: 4384def950bbefc8cdaa49f3bbca41dc2d98f097 27320 redis-sentinel_8.0.2-3+deb13u3_armhf.deb 34d051bfceff3c97f8ecb30fd734fbc2effb05fc 67364 redis-server_8.0.2-3+deb13u3_armhf.deb 9128c2c0a5cd2b3659c4cf067738024f5397d216 4150036 redis-tools-dbgsym_8.0.2-3+deb13u3_armhf.deb af96cdfed0e24cb4793cb28790f1467d77b0192a 1127840 redis-tools_8.0.2-3+deb13u3_armhf.deb 265118516afe19025aaf5652499778e54931cf3b 7416 redis_8.0.2-3+deb13u3_armhf-buildd.buildinfo Checksums-Sha256: 1fa4d43fbd763f6b3f36d98004215564a7f8c59f26dcafdd6a2247e1e0428961 27320 redis-sentinel_8.0.2-3+deb13u3_armhf.deb 9191d72a518b1a05dada6692c21babe281d872eceb68f56a49f8763e31965208 67364 redis-server_8.0.2-3+deb13u3_armhf.deb a53dd95214ff9a0826e6d0ab446bcec1b713b72699b6bed82edf3788672ee295 4150036 redis-tools-dbgsym_8.0.2-3+deb13u3_armhf.deb e95c8041c393ed2ad3c5932cef7bc4d10061d9ec5244ce9acbe1044cea2fdf3e 1127840 redis-tools_8.0.2-3+deb13u3_armhf.deb 67ec1f2eae6cf4a2a1b7c989779764dbb77778a44c9bf3a32cdd987b54b3694c 7416 redis_8.0.2-3+deb13u3_armhf-buildd.buildinfo Files: 52dc6519eafd43dd8a5c4c0a4b1637e4 27320 database optional redis-sentinel_8.0.2-3+deb13u3_armhf.deb fddfc619a95812a1826b4cbf483e8b55 67364 database optional redis-server_8.0.2-3+deb13u3_armhf.deb 9267c406558b6d1eae4ed4599e8ee3fd 4150036 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_armhf.deb 8694e073113b3c6402aa87217fb9c6e1 1127840 database optional redis-tools_8.0.2-3+deb13u3_armhf.deb 63f8531f84f8fc2233abc907f9789c02 7416 database optional redis_8.0.2-3+deb13u3_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEa5s+5E+WDkV2pQjwIyDMsRzdi8EFAmq86GcACgkQIyDMsRzd i8H1+A/+McCRaQKUz/6ttuhOwvA/poauKH+3AG7MmuJSA6dVDN+aoBOh/6ZwxDMS +gHOS2J2EnXN301gmoWl1+J70s43uO9TFZAtUowHpD6dv9X55BHKOtFhSiWA6w6l p/+3FpznMMtCCJT/Kr2zTcR+0svL34lc9HGnk2dFxw3cWRCYPDxyWZq07+FSTUhn eGfRcsO2LFwZ9HrATAjd8kDMihqWFlb7yRPwT0sUO8E9a2WxwijXhbGqqtE/m5hp xJ/LR2zpmpt8RKvVY2Vg335/aAnQfJ/JZ6V4rPTRdmOTXAo02LRrD+HUBbz2hB63 jwcutoMT9F8Yf/YLau6zdhrpuIXaRKvLEJ3K04HULuH5Xderbe5k+1Y+TvZxSWJF 4/KaEdiQlaHdPPD8m+hK3Pgf8gtwJDhlSTldaGXXcCjC7r7rXnYocPz36yKqTDjJ iOx9u85bNfSkXGG71k5jlryRJVbqPoF1R4SaD/I9ZDD2keusHL3QmTd8CYC5xBrR IPyypCMy0/Ggr5ooDO0OIeSaHlXJgxUZZYMeXV+Lw+IbeG6h9bUU/5UENRNTB0En bHAfMb0IADMgFGeQZvBDK8fOnaIuej756X6Zz1uQfkuHvjTJdJodMuAb5BDFjiji CCcWnz8Fak5HpIvGUxLMMN/kC409zIYg9ol5LLJ1m7j5qbrBESI= =HXYr -----END PGP SIGNATURE-----