-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Architecture: source Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: Chris Lamb <lamby@debian.org> Changed-By: Aron Xu <aron@debian.org> Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: 83acdb59ebe5c13300675270aa9bf00de981c89e 1915 redis_8.0.2-3+deb13u3.dsc 7de09e28a46839ddb1f796c7a06d122fa17d11ef 60272 redis_8.0.2-3+deb13u3.debian.tar.xz ec6117075435f2786cc15223f415b764df953923 6230 redis_8.0.2-3+deb13u3_source.buildinfo Checksums-Sha256: 31ba0def05d365d9d91691dd559a0026e5e9aa3f30892bc9a68fbd5d4f8a5625 1915 redis_8.0.2-3+deb13u3.dsc 10d40bb9c0a8a3efd6f3d00850fdfafa5f128e842f47a2fbf0d50b3f70e62943 60272 redis_8.0.2-3+deb13u3.debian.tar.xz d1495e2c9ade69ae7c85742f55c836e92a725e46be26ae5211f3c648994f8481 6230 redis_8.0.2-3+deb13u3_source.buildinfo Files: abe51fbd82c2c7b09d7eed816319bb88 1915 database optional redis_8.0.2-3+deb13u3.dsc 77ff3555b964e4d125b41ecbaef834bc 60272 database optional redis_8.0.2-3+deb13u3.debian.tar.xz 709cea0e7beb73145bd02c4406dac326 6230 database optional redis_8.0.2-3+deb13u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmq82LwACgkQ+GQ1dHE8 m64wvwf/S3xKoM0J51lK9xW/Palz2mrwZJdyK/cOZTktynSBMCAfr9I/7J1KymXT CDlw8xKiNhywRSZaodEpH0AQR+EPFRmFwZ5mBgGqc+3WV8O/ecql+KSVVLotrSRf 7uqHefB1FVXi8taY9me4GRkbMcq1rB7ICpyQ44lMO9o6Dpty+VtDFbVUyFJGaSOF 6w3asfwQHsN3CR5iyjvAIvPYKncS6bfDwhXeSUt25uxVcyCIUPGuRhVZcHTDpBZ7 Y+uQmsivxvNP5On0Nc4bbEoRWstCK0ICj8978ZicAYtAYuTL9kxzrr1ot7ixtDU7 Dng4y5wCl4bD+I5czpvP4tzihrhl1Q== =H+4V -----END PGP SIGNATURE-----