-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym Architecture: arm64 Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: arm64 Build Daemon (arm-ubc-02) Changed-By: Aron Xu Description: redis-sentinel - Persistent key-value database with network interface (monitoring) redis-server - Persistent key-value database with network interface redis-tools - Persistent key-value database with network interface (client) Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: 85470df23feca5c0c36a11a7d6f13329f6b0afc6 27320 redis-sentinel_8.0.2-3+deb13u3_arm64.deb 80157f010f9688609346c021baa66c0e5391fe6a 67364 redis-server_8.0.2-3+deb13u3_arm64.deb 269f6c882970ef64e7bfb83b76472be6c0001f29 4478776 redis-tools-dbgsym_8.0.2-3+deb13u3_arm64.deb 38e9dc3a3134067a6ddca23faa998105ec1a6074 1149976 redis-tools_8.0.2-3+deb13u3_arm64.deb 82c143a1a66fa1f46891dfcf4c743e312066d189 7534 redis_8.0.2-3+deb13u3_arm64-buildd.buildinfo Checksums-Sha256: 42be5b174ca5deebfaa6a3ea4a6b77b09360c4e8e20bae297067befc988d8204 27320 redis-sentinel_8.0.2-3+deb13u3_arm64.deb e638c371d228c1893508bc3dfc07c370e50df08d1f2b1b64ed40f15b4cf767c0 67364 redis-server_8.0.2-3+deb13u3_arm64.deb f73ed9097e54fdfab6d4b9093cc5bdb52347fb31973899e46f7e2d13d3c37b22 4478776 redis-tools-dbgsym_8.0.2-3+deb13u3_arm64.deb 830bfd0aa739a4cfb1524df0958583eff395bfe2b7458fa06d0eef2fcdf5d272 1149976 redis-tools_8.0.2-3+deb13u3_arm64.deb d130b39d78d2a2c295da5a9062d79ee019b7960aa61f88a8316fd34c124bde43 7534 redis_8.0.2-3+deb13u3_arm64-buildd.buildinfo Files: d4de3bf7a180e7560381504d3847c95d 27320 database optional redis-sentinel_8.0.2-3+deb13u3_arm64.deb da3422df3c54afab0bb72af4c7666395 67364 database optional redis-server_8.0.2-3+deb13u3_arm64.deb 6ee8ef26946bfda07e7c9e8e7bf07cfd 4478776 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_arm64.deb f152dab3649e891c426e7c9f3e4d17a2 1149976 database optional redis-tools_8.0.2-3+deb13u3_arm64.deb 3146bad7d95cd2d8655a404e8b7cb994 7534 database optional redis_8.0.2-3+deb13u3_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEJkN0BnKzGWWW6tS+G5VHrWJmwgcFAmq857IACgkQG5VHrWJm wgdEGRAAqaj9GRyqx7+nrZqA9byeAH2WGz+kIldCy97q1xI+NmXRZs0nKaewlEge /6vUG78MP321jmi2nCmv+nyq3lWw1gBfwJBD91nws57XgeaTn8hHHoUfKy3GpqT/ BWsPlkfuslVUqNtO63i3jNZjqNkX7rg1UmWszXlGywGa1gB81HuH9xF3bLj0EBOm qCGTK/m5bkrILeDfFXlmpF0JPKQia3qTjLldYmdvH5TxCsu5L9NKWchVjfQrM9KD VCXRKsWeGAY6IBGiPtnnk4MDsJxRI9abC/oZdUkJ2NIzaw2+PUFOtqW+RhDX7PsB gao3ZTGdxeyoW1BUHbKzNp35strBVGfzffCeIy9Z20Yxj3m5IKLjaxKJSJ+o6azB mlY33u7nCTPaF7ujZkZ28mZ9wmNcUHiAq436X3jI4mnep+ECZmZx+4lSLcLQyMe9 TE/YDU+0vO1cU6M7bLx8wYwPon3p1hdawh/jWZofOGn7ElL5TIAWSDFcZiThzgmK IplvoGeDbFS0W3GEzIELUuxZNPijYfFGjcTlr7jCk7VWT0FoiWARn1yB0HnGUm0u S9ttSdESQ/nURQ6LlR/JXxilntK3PjUICZJDxsb/8gwXk76Km+WziQYJ42/1GhL+ 77FRpajQiJj3Gafwba2DCU7cWbdPSn3uneyieuDCKwYA5f1bPGc= =dF/d -----END PGP SIGNATURE-----