Hi, The following vulnerabilities were published for redis and are fixed in 8.6.3 and later: CVE-2026-23479[0]: | Redis is an in-memory data structure store. In redis-server from | 7.2.0 until 8.6.3, the unblock client flow does not handle an error | return from `processCommandAndResetClient` when re-executing a | blocked command. If a blocked client is evicted during this flow, an | authenticated attacker can trigger a use-after-free that may lead to | remote code execution. This has been patched in version 8.6.3. https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3 https://www.zeroday.cloud/blog/redis-cve-2026-23479-deep-dive Fixed by: https://github.com/redis/redis/commit/c14e9925e571c3c8ecbeb8632fe834faa32175ea (8.6.3) CVE-2026-23631[1]: | Redis is an in-memory data structure store. In all versions of | redis-server with Lua scripting, an authenticated attacker can | exploit the master-replica synchronization mechanism to trigger a | use-after-free on replicas where replica-read-only is disabled or | can be disabled, which may lead to remote code execution. A | workaround is to prevent users from executing Lua scripts or avoid | using replicas where replica-read-only is disabled. This is patched | in version 8.6.3. https://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826 https://www.zeroday.cloud/blog/redis-cve-2026-23631-dark-replica Fixed by: https://github.com/redis/redis/commit/0cca172a174642bdae03b871615227896274d9bb (8.6.3) CVE-2026-25243[2]: | Redis is an in-memory data structure store. In versions of redis- | server up to 8.6.3, the RESTORE command does not properly validate | serialized values. An authenticated attacker with permission to | execute RESTORE can supply a crafted serialized payload that | triggers invalid memory access and may lead to remote code | execution. A workaround is to restrict access to the RESTORE command | with ACL rules. This is patched in version 8.6.3. https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4 https://www.zeroday.cloud/blog/redis-cve-2026-25243-deep-dive Fixed by: https://github.com/redis/redis/commit/b9dde6fc25dec6191b18374335a076a7b31e3d02 (8.6.3) If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-23479 https://www.cve.org/CVERecord?id=CVE-2026-23479 [1] https://security-tracker.debian.org/tracker/CVE-2026-23631 https://www.cve.org/CVERecord?id=CVE-2026-23631 [2] https://security-tracker.debian.org/tracker/CVE-2026-25243 https://www.cve.org/CVERecord?id=CVE-2026-25243 Please adjust the affected versions in the BTS as needed.
We believe that the bug you reported is fixed in the latest version of
redis, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1147421@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Chris Lamb <lamby@debian.org> (supplier of updated redis package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 24 Sep 2026 13:53:38 -0700
Source: redis
Architecture: source
Version: 5:8.0.6-3
Distribution: unstable
Urgency: high
Maintainer: Chris Lamb <lamby@debian.org>
Changed-By: Chris Lamb <lamby@debian.org>
Closes: 1147421 1147422 1147423 1148265
Changes:
redis (5:8.0.6-3) unstable; urgency=high
.
* CVE-2026-23479: The unblock client flow did not handle an error return from
processCommandAndResetClient when re-executing a blocked command. If a
blocked client was evicted during this flow, an authenticated attacker
could have triggered a use-after-free that may lead to remote code
execution. (Closes: #1147421)
* CVE-2026-23631: An authenticated attacker could have exploited the
master-replica synchronisation mechanism via to trigger a use-after-free on
replicas via Lua scripting, which may have led to remote code execution.
(Closes: #1147421)
* CVE-2026-25243: The RESTORE command did not properly validate serialised
values. An authenticated attacker with permission to execute RESTORE could
have supplied a crafted serialised payload that triggers invalid memory
access and may have led to remote code execution. (Closes: #1147421)
* CVE-2026-66373: Redis was vulnerable to a remote code execution
vulnerability via the RESTORE payload where the same NACK (pending entry) is
referenced by more than one consumer, because deleting both consumers via
XGROUP DELCONSUMER led to a double free. This issue exists because of an
incomplete fix for CVE-2026-25243. (Closes: #1147422)
* CVE-2026-81934: Prevent a use-after-free vulnerability in the handling of
pending TLS data. A remote, unauthenticated attacker may be been able to
execute arbitrary commands with the privileges of the Redis server.
(Closes: #1147423)
* CVE-2026-92925: Prevent an out-of-bounds vulnerability in the handling of
cluster ping extensions. This could have allowed a remote attacker to craft a
malicious packet, leading to an out-of-bounds read when the packet's
payload is processed. (Closes: #1148265)
Checksums-Sha1:
6ef4c3ab4e6931f4738772aaf59c1d0181da53b2 2228 redis_8.0.6-3.dsc
002f272f6ae21bc87816738a37a760f25d1d61f3 42672 redis_8.0.6-3.debian.tar.xz
83765ac881cdcefc04183e368a9ad8795b522ee2 7314 redis_8.0.6-3_amd64.buildinfo
Checksums-Sha256:
1e199379e5098fbc492b7756fa4c829c8938d7d4c467add6266c4abd911ba0c9 2228 redis_8.0.6-3.dsc
1534f644abae0af8a61b1a19a7874b57056decce90b8ed80c0cfd2a7439c8116 42672 redis_8.0.6-3.debian.tar.xz
c81a7f87ca04c80fd8bf20551d7fee34f2c35d44de906f28f36e8419e0a1f816 7314 redis_8.0.6-3_amd64.buildinfo
Files:
a54cbe0f57d97b5735cfb6c153dd96d0 2228 database optional redis_8.0.6-3.dsc
8a2bd883833f0b610d22c8a06a25d700 42672 database optional redis_8.0.6-3.debian.tar.xz
671451dcda72d96863594f128bb3c2e3 7314 database optional redis_8.0.6-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmq1kLkACgkQHpU+J9Qx
HlhUchAAvz8pmFGWd+ryiMcvAfVDLGNtGLtizRw97GPyuF9Zh7yZs7s2irwmGRqw
k6MkAq0mqqR67+2W29XiUF+DkREIwjT2dqrcnXyxdWHQaUsxA6iYKteTpL9F81/w
EQdyBnT/jx7f9ff/xhsXOb8Bu5Fh4Mh0M7+bwMouj6mDjlboN5jZWLbqkRGZvj6B
5L4YxTg1uN600uEFpAjQ7Ru+XC9SybuKIaPWD+JkwEtk+urroHZ8aJAZONcM1qe9
56TLAYTpYikkxaMkWaLpSGLV8fbVMB1IoIvysJsdbtQyTB2vttFd8KheGDpa21xq
0SXZ/8zwbxiYeOCoG7KxQed5/Q/NrM2rHlK7sDjkXwwjxJ+xTNrm/gbk0dmAPO8R
wMyVUsBQUdM+XKziILQ5x42VOdGTXRQkzVbOAQCgOcb8mWaesyRcqwW1gTL1aLbb
qx6ctE/nuB9ujxGXr0SIz6EI/eOxILRRGoxwRKIFsUnzVDFxOK/PwHaUA4cEFl24
kh2qG/rBVBCkm6Pijmm4QDSfgnB6WlurxrYDQxQARAmKCwIZFGJHhpfNnu+vKdTE
kEpySUaRo1rNVjy/hivTjZlD87OOUECycmEi+f7gK8qMyG+qOOezeFs7z4A+EiZP
E4bZX09EhRAND35eK62q5OpPiOUhg7oVcLsa6pquRSzKvm4ofUA=
=39Kj
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
redis, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1147421@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Aron Xu <aron@debian.org> (supplier of updated redis package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 15 Sep 2026 00:52:10 +0800
Source: redis
Architecture: source
Version: 5:8.0.2-3+deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: Chris Lamb <lamby@debian.org>
Changed-By: Aron Xu <aron@debian.org>
Closes: 1147421 1147422 1147423
Changes:
redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high
.
* Non-maintainer upload by the Security Team.
* CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE
command did not properly validate serialized values; an
authenticated attacker able to run RESTORE could supply a crafted
payload triggering invalid memory access and possibly remote code
execution. (Closes: #1147421)
* CVE-2026-23631: Lua use-after-free on replicas. An authenticated
attacker could exploit the master-replica synchronization mechanism
to trigger a use-after-free on replicas where replica-read-only is
disabled, potentially leading to remote code execution.
(Closes: #1147421)
* CVE-2026-23479: Use-after-free in the unblock client flow. The error
return from processCommandAndResetClient was not handled when re-
executing a blocked command, allowing an authenticated attacker to
trigger a use-after-free and possibly remote code execution.
(Closes: #1147421)
* CVE-2026-66373: Double free via RESTORE of a stream whose NACK is
shared by several consumers, an incomplete fix for CVE-2026-25243;
deleting both consumers with XGROUP DELCONSUMER could lead to remote
code execution. (Closes: #1147422)
* CVE-2026-81934: Use-after-free in tlsProcessPendingData() when
handling the TLS pending-data list. A remote unauthenticated
attacker may be able to execute arbitrary code with the privileges
of the server. (Closes: #1147423)
* Some important fixes upstream shipped as security fixes without CVE:
- From 8.2.9: ACL key-permission bypass in SORT,
GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv
access during ACL key extraction for wrong-arity KEYNUM commands,
out-of-range SLOT_INFO slot id in RDB loading causing memory corruption,
and a use-after-free in handleClientsBlockedOnKey when reprocessing a
command evicts another client blocked on the same key.
- From 8.0.5: out-of-bounds argv read and crash in HGETEX when the
FIELDS option lacks its numfields argument, and an integer overflow in
the HyperLogLog MurmurHash64A with entries over 2GB.
Checksums-Sha1:
83acdb59ebe5c13300675270aa9bf00de981c89e 1915 redis_8.0.2-3+deb13u3.dsc
7de09e28a46839ddb1f796c7a06d122fa17d11ef 60272 redis_8.0.2-3+deb13u3.debian.tar.xz
ec6117075435f2786cc15223f415b764df953923 6230 redis_8.0.2-3+deb13u3_source.buildinfo
Checksums-Sha256:
31ba0def05d365d9d91691dd559a0026e5e9aa3f30892bc9a68fbd5d4f8a5625 1915 redis_8.0.2-3+deb13u3.dsc
10d40bb9c0a8a3efd6f3d00850fdfafa5f128e842f47a2fbf0d50b3f70e62943 60272 redis_8.0.2-3+deb13u3.debian.tar.xz
d1495e2c9ade69ae7c85742f55c836e92a725e46be26ae5211f3c648994f8481 6230 redis_8.0.2-3+deb13u3_source.buildinfo
Files:
abe51fbd82c2c7b09d7eed816319bb88 1915 database optional redis_8.0.2-3+deb13u3.dsc
77ff3555b964e4d125b41ecbaef834bc 60272 database optional redis_8.0.2-3+deb13u3.debian.tar.xz
709cea0e7beb73145bd02c4406dac326 6230 database optional redis_8.0.2-3+deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmq82LwACgkQ+GQ1dHE8
m64wvwf/S3xKoM0J51lK9xW/Palz2mrwZJdyK/cOZTktynSBMCAfr9I/7J1KymXT
CDlw8xKiNhywRSZaodEpH0AQR+EPFRmFwZ5mBgGqc+3WV8O/ecql+KSVVLotrSRf
7uqHefB1FVXi8taY9me4GRkbMcq1rB7ICpyQ44lMO9o6Dpty+VtDFbVUyFJGaSOF
6w3asfwQHsN3CR5iyjvAIvPYKncS6bfDwhXeSUt25uxVcyCIUPGuRhVZcHTDpBZ7
Y+uQmsivxvNP5On0Nc4bbEoRWstCK0ICj8978ZicAYtAYuTL9kxzrr1ot7ixtDU7
Dng4y5wCl4bD+I5czpvP4tzihrhl1Q==
=H+4V
-----END PGP SIGNATURE-----