-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 24 Sep 2026 13:53:38 -0700 Source: redis Architecture: source Version: 5:8.0.6-3 Distribution: unstable Urgency: high Maintainer: Chris Lamb <lamby@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Closes: 1147421 1147422 1147423 1148265 Changes: redis (5:8.0.6-3) unstable; urgency=high . * CVE-2026-23479: The unblock client flow did not handle an error return from processCommandAndResetClient when re-executing a blocked command. If a blocked client was evicted during this flow, an authenticated attacker could have triggered a use-after-free that may lead to remote code execution. (Closes: #1147421) * CVE-2026-23631: An authenticated attacker could have exploited the master-replica synchronisation mechanism via to trigger a use-after-free on replicas via Lua scripting, which may have led to remote code execution. (Closes: #1147421) * CVE-2026-25243: The RESTORE command did not properly validate serialised values. An authenticated attacker with permission to execute RESTORE could have supplied a crafted serialised payload that triggers invalid memory access and may have led to remote code execution. (Closes: #1147421) * CVE-2026-66373: Redis was vulnerable to a remote code execution vulnerability via the RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER led to a double free. This issue exists because of an incomplete fix for CVE-2026-25243. (Closes: #1147422) * CVE-2026-81934: Prevent a use-after-free vulnerability in the handling of pending TLS data. A remote, unauthenticated attacker may be been able to execute arbitrary commands with the privileges of the Redis server. (Closes: #1147423) * CVE-2026-92925: Prevent an out-of-bounds vulnerability in the handling of cluster ping extensions. This could have allowed a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. (Closes: #1148265) Checksums-Sha1: 6ef4c3ab4e6931f4738772aaf59c1d0181da53b2 2228 redis_8.0.6-3.dsc 002f272f6ae21bc87816738a37a760f25d1d61f3 42672 redis_8.0.6-3.debian.tar.xz 83765ac881cdcefc04183e368a9ad8795b522ee2 7314 redis_8.0.6-3_amd64.buildinfo Checksums-Sha256: 1e199379e5098fbc492b7756fa4c829c8938d7d4c467add6266c4abd911ba0c9 2228 redis_8.0.6-3.dsc 1534f644abae0af8a61b1a19a7874b57056decce90b8ed80c0cfd2a7439c8116 42672 redis_8.0.6-3.debian.tar.xz c81a7f87ca04c80fd8bf20551d7fee34f2c35d44de906f28f36e8419e0a1f816 7314 redis_8.0.6-3_amd64.buildinfo Files: a54cbe0f57d97b5735cfb6c153dd96d0 2228 database optional redis_8.0.6-3.dsc 8a2bd883833f0b610d22c8a06a25d700 42672 database optional redis_8.0.6-3.debian.tar.xz 671451dcda72d96863594f128bb3c2e3 7314 database optional redis_8.0.6-3_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmq1kLkACgkQHpU+J9Qx HlhUchAAvz8pmFGWd+ryiMcvAfVDLGNtGLtizRw97GPyuF9Zh7yZs7s2irwmGRqw k6MkAq0mqqR67+2W29XiUF+DkREIwjT2dqrcnXyxdWHQaUsxA6iYKteTpL9F81/w EQdyBnT/jx7f9ff/xhsXOb8Bu5Fh4Mh0M7+bwMouj6mDjlboN5jZWLbqkRGZvj6B 5L4YxTg1uN600uEFpAjQ7Ru+XC9SybuKIaPWD+JkwEtk+urroHZ8aJAZONcM1qe9 56TLAYTpYikkxaMkWaLpSGLV8fbVMB1IoIvysJsdbtQyTB2vttFd8KheGDpa21xq 0SXZ/8zwbxiYeOCoG7KxQed5/Q/NrM2rHlK7sDjkXwwjxJ+xTNrm/gbk0dmAPO8R wMyVUsBQUdM+XKziILQ5x42VOdGTXRQkzVbOAQCgOcb8mWaesyRcqwW1gTL1aLbb qx6ctE/nuB9ujxGXr0SIz6EI/eOxILRRGoxwRKIFsUnzVDFxOK/PwHaUA4cEFl24 kh2qG/rBVBCkm6Pijmm4QDSfgnB6WlurxrYDQxQARAmKCwIZFGJHhpfNnu+vKdTE kEpySUaRo1rNVjy/hivTjZlD87OOUECycmEi+f7gK8qMyG+qOOezeFs7z4A+EiZP E4bZX09EhRAND35eK62q5OpPiOUhg7oVcLsa6pquRSzKvm4ofUA= =39Kj -----END PGP SIGNATURE-----