-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym Architecture: i386 Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Aron Xu Description: redis-sentinel - Persistent key-value database with network interface (monitoring) redis-server - Persistent key-value database with network interface redis-tools - Persistent key-value database with network interface (client) Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: 7504edb6f2c8c8bb5f90350c9eb58cfbde725f6e 27320 redis-sentinel_8.0.2-3+deb13u3_i386.deb bb9dada2ead2e7ac4a5b877f952ed8250c78ad49 67364 redis-server_8.0.2-3+deb13u3_i386.deb 439263eff2d0e03fbfe4b30b7cb87e34bdd85a3e 4171096 redis-tools-dbgsym_8.0.2-3+deb13u3_i386.deb f3910420e93076161539a5c5b7811ba21bca3e62 1263368 redis-tools_8.0.2-3+deb13u3_i386.deb 449beb6ee64a545de8f10cca80f05c0f75b56f99 7445 redis_8.0.2-3+deb13u3_i386-buildd.buildinfo Checksums-Sha256: 07791fcaf46d4d3f0c69b8b5d5aaf253814970199f19e0439c8a234ae92696bc 27320 redis-sentinel_8.0.2-3+deb13u3_i386.deb c72b5eb116ef8c8b5419a0ff773f0d054b7bcaa95bc549582bbc767b05da5555 67364 redis-server_8.0.2-3+deb13u3_i386.deb 0cca390294357549243d34200550617c1fa933873d74a1758d43ae2d6cf57c75 4171096 redis-tools-dbgsym_8.0.2-3+deb13u3_i386.deb f262fb65e8f106c2c2c03e87018c076e4d4bb36610de2a9dc5d55fd9aa0c9f53 1263368 redis-tools_8.0.2-3+deb13u3_i386.deb 4f4ba4cc2b13577d58c5cd46f934e3eb91ae0749135ed45b1bd23dfd73047cdf 7445 redis_8.0.2-3+deb13u3_i386-buildd.buildinfo Files: 237d3b0e60db7a8f58fc3c277242935a 27320 database optional redis-sentinel_8.0.2-3+deb13u3_i386.deb 4cee5e561a0e666e62d9899d2ac97c6f 67364 database optional redis-server_8.0.2-3+deb13u3_i386.deb d943d36bbf788f74a4478e56bf66dea3 4171096 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_i386.deb e8896884bd1bde54f6d2acbe8da950e6 1263368 database optional redis-tools_8.0.2-3+deb13u3_i386.deb 01fdb395e989667a10acd4c765dd0fef 7445 database optional redis_8.0.2-3+deb13u3_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmq86ekACgkQf2INRiCd aWIv9g/+MbbDLVYOEj0xZv3Iam6LDvvgVV/qa3V/lpfmxliTR1bRNgRmavJ2ceP2 Wxnvv1bhVZVbVKkggQN0iizcV/OAdqmdqRLYUZ5M8YiVGZX7OSKAjP5yYmYv27Uk zx4MclHC4LItwyt/ck4ux4ZZfv7JbsZqCbzmWFCSL3hf4m9vS2qGIWQlsh+NeQFA VpdZZR5B8mwlup8Bcygb3uvE/lqq7/EwYQo3iTZzVDW/cAgAs5ddp9T6HSTAGSbK k7p/HfGCuQMF4aJ0IYNiUinG8zzPjZDWqQIYe1I7vczEt3SU5unRhFfkL9fq46A3 2HNxnhehd/w0+vFxwmo0KA7SSTVyU033kQ3MNo2X0jqLL4FdZwL1xAwsHeKG4qB5 SUTLRoBTSz33x4HBJMPVioDtFS0hIEkSpzlf4EcAMQ9cZGMYbMqpjfpvuX0H33Y0 XNucQ9i7+bWoEWEBTE/gPRY+hJaizlIWyk7azZNQihClReFd0XH3AUwwh2DRNYIl nZjbDveW4rUpSlKwzGSwdvS2LT09OQMbTG/+BYoYKyXu42tam5wi6vQNO5CaqCCN RTCNdF0JNZc2QuNUEeN6j2dasrZdwauY4zmlv26N/xiWGFJIGzm6HYuZHBiSp36f mp/ir8d9tRTxaHpNwEN8j9np0RtH29TULTmsf/k63GBUqIaYckA= =8LCU -----END PGP SIGNATURE-----