-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym Architecture: amd64 Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Aron Xu Description: redis-sentinel - Persistent key-value database with network interface (monitoring) redis-server - Persistent key-value database with network interface redis-tools - Persistent key-value database with network interface (client) Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: 8147e9e912bc1141949808bc99a8af57fcfb327b 27320 redis-sentinel_8.0.2-3+deb13u3_amd64.deb e86e15cf9ec82d8400a24232abeab3bd63b49f0d 67364 redis-server_8.0.2-3+deb13u3_amd64.deb cbd97c7ea09f576914ad56c63fbbe32ab931cb60 4535320 redis-tools-dbgsym_8.0.2-3+deb13u3_amd64.deb 0e9df7ee04a61c7c0b7cc358c1bcdd96b7a38fc6 1247524 redis-tools_8.0.2-3+deb13u3_amd64.deb 1249d350ace5ca9082875a928c9a39e22793bfb7 7550 redis_8.0.2-3+deb13u3_amd64-buildd.buildinfo Checksums-Sha256: 54732ca16aababaae3c4cb0dd1f6505993fd69ec207ccc19b2276f1e10e65804 27320 redis-sentinel_8.0.2-3+deb13u3_amd64.deb 16b5435d05745503f29c8b4ced5bdce3e800ae5370d5f70e6519664d7515cb0f 67364 redis-server_8.0.2-3+deb13u3_amd64.deb 8f753e4c89dc4d4cd89a19ef1ae81ab889d1226cc39f885fd45c00e9abab9640 4535320 redis-tools-dbgsym_8.0.2-3+deb13u3_amd64.deb ca91969383b5e9ea7f278dde513e2bc444914961e19e7d94cda7745a95f6686a 1247524 redis-tools_8.0.2-3+deb13u3_amd64.deb d1fe67890f3b31c7881601f6f7e66b68e4aae1feb656fbca8d9a25f7da0a1e12 7550 redis_8.0.2-3+deb13u3_amd64-buildd.buildinfo Files: 5ceae37f14f54439ac8e9597459b4767 27320 database optional redis-sentinel_8.0.2-3+deb13u3_amd64.deb 2f92e48919130efb1ac934c592b10624 67364 database optional redis-server_8.0.2-3+deb13u3_amd64.deb 7b3e8b99de06443b83e655c470a2d671 4535320 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_amd64.deb 967fc4dd2c9523855f6c3f1f636c933d 1247524 database optional redis-tools_8.0.2-3+deb13u3_amd64.deb 351784a7f2d981d3436a98f6c9c6674a 7550 database optional redis_8.0.2-3+deb13u3_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmq856YACgkQTwt/65ON 6zfGmxAAh2/gyMUQcHj+x10TWtxZ7pmeo2XfUGBTMO+m+3BKZjsA1UHVHEB4zFFh Rez1RiyrcybNLStSPpUkxVr5X7UnRu1gtB2dmbp7vbzuZfLl9f04S2rp3N4xf8ZH Zf1zwZu8DgTD/Ap0Ar9V6dbrTE5IPogsT/3zw5fcYGTVQL3L1rmnUFwsXHS6/Wdh CqpMMF0ngDZKABcCsWxAcCMKwaX3s+vGbcb1kU/LT0g0CKVwt6an9F6RD8pgX4NZ FIPU8d0aPxGMbxwHCiWwWqeTwX+Lmf6byAjBhovjEPaDiqoGq27U+85pjDZsn18B HFH5bNO8T4t/1WpAavxAgOFHAzsEyDkoPPg4sP7+HjtvMLiGtEqB14/twvHJQdXw upTkafuBstyP/hBT+3Au60y7FZ9rbnJaGRD3w9ETMyGqe4ZUUJ/jUykAK//aXz9I 8p1rKBv4m5yW/cEb4YOHwXbQMq27veNA9sxcjZjN9H4JuE4ZAKDNeWXv43IAu1M1 Zhe2/vwyVIzv6AccmneFhJm5B1ZI+HoKCbeIVkm+LrBIWJDBqAYY2dJ9/9Tt7K8M dYzoPt/EWA0x774HnzWbLwWR9WUqnwFfyaSjijbxWDrwy+H+OfKfJSaSpubfLkc+ 0th30Wxa6C7i5D0GTNZTanCaJ7DtPqL0uyS+wDia4zXUkTGE1GM= =6UTz -----END PGP SIGNATURE-----