-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym Architecture: ppc64el Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Aron Xu Description: redis-sentinel - Persistent key-value database with network interface (monitoring) redis-server - Persistent key-value database with network interface redis-tools - Persistent key-value database with network interface (client) Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: cd3535411d10c5e2c759ec37980bdffc400e1c25 27320 redis-sentinel_8.0.2-3+deb13u3_ppc64el.deb cf9587970d4a2c06734711b6d2505000f0aea3ac 67364 redis-server_8.0.2-3+deb13u3_ppc64el.deb 1968663ae76bc6784662b60f01f7681be5363810 4238336 redis-tools-dbgsym_8.0.2-3+deb13u3_ppc64el.deb f3ada72d1102d58a2af4922ccb78cfd241b6f524 1311276 redis-tools_8.0.2-3+deb13u3_ppc64el.deb 3da7eab5fdd024ed6e2118d22908eb700ad40d13 7561 redis_8.0.2-3+deb13u3_ppc64el-buildd.buildinfo Checksums-Sha256: 46f1235de8198f1b3cf38d13e65324040b5ade8273ac8ac669dcf57ea98938ab 27320 redis-sentinel_8.0.2-3+deb13u3_ppc64el.deb 0dc6244b646ea045728468731e6404eacca7bed2683094171885de8253aa8f21 67364 redis-server_8.0.2-3+deb13u3_ppc64el.deb a0d0f7545a4bf8eff5e174d7b54e9ed47c4675d659271274f66a29f9a44eb5c5 4238336 redis-tools-dbgsym_8.0.2-3+deb13u3_ppc64el.deb f22b73ece7518df6884eac4ff88b11cfd05c4692b4bb9bec4eb0d941c9c7aa5a 1311276 redis-tools_8.0.2-3+deb13u3_ppc64el.deb 928ed9b5096d9bc73cfdb741b5a75090405e4eed0db5a50d3dcd150d341af927 7561 redis_8.0.2-3+deb13u3_ppc64el-buildd.buildinfo Files: 2176d537eb72364140f56c99c7df2a3e 27320 database optional redis-sentinel_8.0.2-3+deb13u3_ppc64el.deb 9b165cca4a83dc5e9a10e3d09e71b8a4 67364 database optional redis-server_8.0.2-3+deb13u3_ppc64el.deb 8a573d1f4985f846d340b75c2da428d6 4238336 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_ppc64el.deb 2c3cf9e3b65087dcae91b0e66380ddc2 1311276 database optional redis-tools_8.0.2-3+deb13u3_ppc64el.deb bf912c221e86587816d45fb7d98dd012 7561 database optional redis_8.0.2-3+deb13u3_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDoRc43uRWMOoIqIgDNLUPhbmg7MFAmq85wQACgkQDNLUPhbm g7O+EhAAnCiU6ANbSuhzXYd+Q1QJByl9P356JCoW5q38BSrnjALlzak5XgwDugJY X3dx85E+7v6+ntHrNwdC+v7BaRVgbBxkR8IBXoHyx7ulOyVyW1cVmpUUT/DN1w20 3CfwVo4aPn3knhxczpdQOs9DrbzAcTsMspL1BZO0aA/xh5dlBgYLDbr0bigYdtOZ XsYLou00lNL20i4Lt6P5LUlKBHNNC+75rr8FLyRCAIap0zOPr9WosiNMnrAtyiXC 641xroCZN2Rz9i+vqIxD1I+1WJLSr2zFkPPoxZ3JRoKX0iMxf0kqGWh0BIjmQV69 6I4jTCjFfJCW1gf4/z+yGz3FcymIlf7Y+IO6hRZMHnkXHA71D+R2i+WYiihFJmkH H5ZBhI6sgNPUFKFmi1F5YQJatwnhE7tpzXoYJZIMhjd1gjFbHchvaSwldun+p1RE qFp911uhatqjAtboeJaIGzKtyllc4AkOg5/cn/t0i51lV0C9Z6RS+ONegjTMLaQl 6zSVoqeBM51af+gBbtIQU8QHr7CdNVKDRaGfyef0KI4OtWaIo3g/dZ6EQP1DyamL BxEKU6Zt8i+BnnJqAKxFbdJKXKi4YHrmSC+6FZ1VyifEzxWJn1v7HhthD/iXYMH+ cY9BmAyk2x9j+cRV1oenLrw8RrIkDcGPaulR4tDsS2Lv4hetqoQ= =mZf7 -----END PGP SIGNATURE-----