-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym Architecture: riscv64 Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: riscv64 Build Daemon (rv-manda-04) Changed-By: Aron Xu Description: redis-sentinel - Persistent key-value database with network interface (monitoring) redis-server - Persistent key-value database with network interface redis-tools - Persistent key-value database with network interface (client) Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: ab832e4899063707f05e2cfcd1bb2ef9064e433d 27320 redis-sentinel_8.0.2-3+deb13u3_riscv64.deb 5016b61521a2d4703126daf2a682e14d2fff1b72 67364 redis-server_8.0.2-3+deb13u3_riscv64.deb 308def566f9481ce8d20b54a657f34a480d3baec 4290088 redis-tools-dbgsym_8.0.2-3+deb13u3_riscv64.deb cf989ba7fe0419f98550e9c642a9068e8afc770e 1307116 redis-tools_8.0.2-3+deb13u3_riscv64.deb fe50915a164bd531e52e4b210b158b92784f6f0c 7506 redis_8.0.2-3+deb13u3_riscv64-buildd.buildinfo Checksums-Sha256: f37fd4a095e4da20595c89a1f4daf505fe66f072310c2a29d035ec9e946acdfb 27320 redis-sentinel_8.0.2-3+deb13u3_riscv64.deb b4ac454393b15ec37b4a27f1e30b2d0d031d36ca13d353d71966bd0906ac1ce5 67364 redis-server_8.0.2-3+deb13u3_riscv64.deb 65d329939a1ceb3ff3abd468d375d0faac18a5691dce276f0523662e1bf7d3a2 4290088 redis-tools-dbgsym_8.0.2-3+deb13u3_riscv64.deb 5a7d3766949dab17b4b5b133ede4dfaea670dcad9779ffc471170685e7fa9a13 1307116 redis-tools_8.0.2-3+deb13u3_riscv64.deb 3036cb023aecc013489f73635ea8cadb02b1f98e712e1fd2517a2b3dce997687 7506 redis_8.0.2-3+deb13u3_riscv64-buildd.buildinfo Files: ef9efdb7207bbdfc856210aa71c5ee98 27320 database optional redis-sentinel_8.0.2-3+deb13u3_riscv64.deb 85ae1c1c1e28c889d6a7fe1f16975b80 67364 database optional redis-server_8.0.2-3+deb13u3_riscv64.deb 1d14a805de9005e7147f1948e34d5fe4 4290088 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_riscv64.deb 588a1e398ec055eb6d0eec31a6a04244 1307116 database optional redis-tools_8.0.2-3+deb13u3_riscv64.deb 6c3a1fe8438199614b84ad10814b858b 7506 database optional redis_8.0.2-3+deb13u3_riscv64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpWtAFYomK/29mcYCqTndZcwOQoMFAmq8+lYACgkQqTndZcwO QoPoCxAAl560hLohdn9Q7tGaJZ+NIJkIpShPj6T4wm3itydkKkqeOr83sTE3l12W aVjw8WZJblrbu6rJD0cTEbQvGQrlMuPsVLJNkeZZoDqfUh5AY1MSvDOf3VtLQ3op 24WhXLubV8l+xi+K4NA6vyz+XF3Wtix8vHoTJixJWyH/dW+HIZZgWtCXAFur/Ifh WqqR6XjKCKDHkVFPiaCWOhKLjicmmeSQjjj8H9F54w0YOxxF9hbI2H4+Tr4n715A X5yk2E01hOOE6j2neNOOUcxNdISi1yK9XezAbJGQCB0DuUjZffDU/t8dXv5Q/o12 O/2FhK0c/C0Fat6sFpmYth2aexSCAWgByBhNmE4SCLPtooTuAWMgb5ZoKyr3WVGV 7rfJHByJwi8wh1RkCehQdHE0zep7Uq+CS8hNz7EYQ5n4A6XrMDrun9bNma2WMBER aTTgta2UJWiYWSSsOL9w5za8QrAJxJfvqe2U/1vLdD3djTvyKOEKxd4TvsdZxiCd eTrWwgS+9YzFSrCH6NYs1wq3OPmybE9sAYwLq7H7xdBgZuTc/eGpo09Ktb0QQu0L O/yY7CNULCehNsPhJP75enEO/LIC+i43wLgkv3CPLXZD2fcTzpTcor5FCRFKg49a CSKixdOQtiXfwK8QAsg/97ePmVaSoTX5o4ciQrPktDhISm29OC0= =AgbA -----END PGP SIGNATURE-----