-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym Architecture: armel Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: armel Build Daemon (arm-ubc-03) Changed-By: Aron Xu Description: redis-sentinel - Persistent key-value database with network interface (monitoring) redis-server - Persistent key-value database with network interface redis-tools - Persistent key-value database with network interface (client) Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: 58887b65f69cdf13ebdddf38e92077d829152bc1 27320 redis-sentinel_8.0.2-3+deb13u3_armel.deb 635862936d1d55b041da63bb28415c3c0e9fccfe 67364 redis-server_8.0.2-3+deb13u3_armel.deb cb093d70ca8b4285d2b65a574e1a9fd4f128d6ef 4118304 redis-tools-dbgsym_8.0.2-3+deb13u3_armel.deb d9ce86d0537253da32d4ff720aedb913bc2fa5a3 1119964 redis-tools_8.0.2-3+deb13u3_armel.deb 0e02dba0f311a0d5adcf58093ba5d83a578ccb03 7402 redis_8.0.2-3+deb13u3_armel-buildd.buildinfo Checksums-Sha256: ec7c93777d13bc0af5bc22c198462537afc9561de3b0879dcdb492d87074e174 27320 redis-sentinel_8.0.2-3+deb13u3_armel.deb 81d83e27449068ba8a94e0b3d169b9c6ec0c8f8c60dd3afdcd1644006eb89a62 67364 redis-server_8.0.2-3+deb13u3_armel.deb 4b747a7f94a8ab416b5d29f5829d4144da66c90bcdbe4a458b116c6f0977af05 4118304 redis-tools-dbgsym_8.0.2-3+deb13u3_armel.deb bd353814689955d5bd790ca3cd24aba661f6528316b7823c3fab46ab6018941f 1119964 redis-tools_8.0.2-3+deb13u3_armel.deb 8e627f3bc9fccd11d49495f030df01cc541098d598536c8195c5272f56d24e02 7402 redis_8.0.2-3+deb13u3_armel-buildd.buildinfo Files: 5c70c0bc4e91be474aee972cba295881 27320 database optional redis-sentinel_8.0.2-3+deb13u3_armel.deb 394a4e3e556f7d18dd31e9f1fe2aedbf 67364 database optional redis-server_8.0.2-3+deb13u3_armel.deb 3cfc207a5f245ec6fd703c0c38bd5856 4118304 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_armel.deb f94f794369eac8d7615d22c2fbf9602d 1119964 database optional redis-tools_8.0.2-3+deb13u3_armel.deb ddab9528417b0a116d43f41973c5a1f4 7402 database optional redis_8.0.2-3+deb13u3_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE2kd8oHy+LXk/nybqvzDqKQSGl8UFAmq86dcACgkQvzDqKQSG l8WkzA//eG4c2U+VtR5DxpU91ujvuEIW5x/IF+Y1jHKBfb4GvdO/54d9iA+Ij3Uy xFkyy8QgQ9DUN/HXvEQTmaLLApG2ULg4tVz0KH9EAK0baF2et3V+xBaGCfYvV7ud 5xlJejHvBiRBd+qfTSZxqk95UYlzVnNEMXlHi5f6izXTpPGcMpqw9N7vaWxv05wt Q29jxij9sWeXFO+uOGD8GkLNx8vBVbwvAXIGj/ND86MHqwIwy8r9g+kVIBIYu7EF 4ykB5ENeXSC1bvKgzRccX6TjDBv+S3o81I14yPIJvOtJJddEe+C/dsBsrBkHVGvK xb8jwcfxG29HheN6E3aRPVjvrG7Cynlqdk1sqjUyWbuJGzn0I9Wvowbvoe3A7tTa KmUe9Ug/slzbjLv5tcgL3bURggnoULjw4mmkvGzr07A6QmWr30swIFBkP8RXC11s wPPAPu5du1CfYE8D7m3ubI0DHD3ZLdANu+R22N5BsEZQdGp8QmDqwJwt3t1bTx0m ZH2AeLiQT5rlilAKZuq9G4LcokRlkcJKdzhCgZWpRlQ4JNpP2bDIQ9Lhs8rFX3Y6 nhXvRYSkSO2hDxmC+27k1t15zxq8EYn5naf4TtUX574h7K7pCnKoG7ziVs5DeXxF 8IXdeM3cLVLcOD6jArJOlKJEBsIWDRYV8RZ4LTtq2G9PVDTZDqI= =A2KG -----END PGP SIGNATURE-----