#1147423 redis: CVE-2026-81934

Package:
src:redis
Source:
src:redis
Submitter:
Moritz Mühlenhoff
Date:
2026-09-24 21:21:03 UTC
Severity:
normal
Tags:
#1147423#5
Date:
2026-09-11 17:01:48 UTC
From:
To:
Hi,

The following vulnerability was published for redis.

CVE-2026-81934[0]:
| Redis contains a use-after-free vulnerability in the
| 'tlsProcessPendingData()' function, which handles the TLS pending-
| data list if Redis is configured with TLS support. A remote,
| unauthenticated attacker may be able to execute arbitrary commands
| with the privileges of the Redis server.

https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834 (8.8.2)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-81934
https://www.cve.org/CVERecord?id=CVE-2026-81934

Please adjust the affected versions in the BTS as needed.

#1147423#12
Date:
2026-09-24 21:19:34 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
redis, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147423@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Chris Lamb <lamby@debian.org> (supplier of updated redis package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 24 Sep 2026 13:53:38 -0700
Source: redis
Architecture: source
Version: 5:8.0.6-3
Distribution: unstable
Urgency: high
Maintainer: Chris Lamb <lamby@debian.org>
Changed-By: Chris Lamb <lamby@debian.org>
Closes: 1147421 1147422 1147423 1148265
Changes:
 redis (5:8.0.6-3) unstable; urgency=high
 .
   * CVE-2026-23479: The unblock client flow did not handle an error return from
     processCommandAndResetClient when re-executing a blocked command. If a
     blocked client was evicted during this flow, an authenticated attacker
     could have triggered a use-after-free that may lead to remote code
     execution. (Closes: #1147421)
   * CVE-2026-23631: An authenticated attacker could have exploited the
     master-replica synchronisation mechanism via to trigger a use-after-free on
     replicas via Lua scripting, which may have led to remote code execution.
     (Closes: #1147421)
   * CVE-2026-25243: The RESTORE command did not properly validate serialised
     values. An authenticated attacker with permission to execute RESTORE could
     have supplied a crafted serialised payload that triggers invalid memory
     access and may have led to remote code execution. (Closes: #1147421)
   * CVE-2026-66373: Redis was vulnerable to a remote code execution
     vulnerability via the RESTORE payload where the same NACK (pending entry) is
     referenced by more than one consumer, because deleting both consumers via
     XGROUP DELCONSUMER led to a double free. This issue exists because of an
     incomplete fix for CVE-2026-25243. (Closes: #1147422)
   * CVE-2026-81934: Prevent a use-after-free vulnerability in the handling of
     pending TLS data. A remote, unauthenticated attacker may be been able to
     execute arbitrary commands with the privileges of the Redis server.
     (Closes: #1147423)
   * CVE-2026-92925: Prevent an out-of-bounds vulnerability in the handling of
     cluster ping extensions. This could have allowed a remote attacker to craft a
     malicious packet, leading to an out-of-bounds read when the packet's
     payload is processed. (Closes: #1148265)
Checksums-Sha1:
 6ef4c3ab4e6931f4738772aaf59c1d0181da53b2 2228 redis_8.0.6-3.dsc
 002f272f6ae21bc87816738a37a760f25d1d61f3 42672 redis_8.0.6-3.debian.tar.xz
 83765ac881cdcefc04183e368a9ad8795b522ee2 7314 redis_8.0.6-3_amd64.buildinfo
Checksums-Sha256:
 1e199379e5098fbc492b7756fa4c829c8938d7d4c467add6266c4abd911ba0c9 2228 redis_8.0.6-3.dsc
 1534f644abae0af8a61b1a19a7874b57056decce90b8ed80c0cfd2a7439c8116 42672 redis_8.0.6-3.debian.tar.xz
 c81a7f87ca04c80fd8bf20551d7fee34f2c35d44de906f28f36e8419e0a1f816 7314 redis_8.0.6-3_amd64.buildinfo
Files:
 a54cbe0f57d97b5735cfb6c153dd96d0 2228 database optional redis_8.0.6-3.dsc
 8a2bd883833f0b610d22c8a06a25d700 42672 database optional redis_8.0.6-3.debian.tar.xz
 671451dcda72d96863594f128bb3c2e3 7314 database optional redis_8.0.6-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmq1kLkACgkQHpU+J9Qx
HlhUchAAvz8pmFGWd+ryiMcvAfVDLGNtGLtizRw97GPyuF9Zh7yZs7s2irwmGRqw
k6MkAq0mqqR67+2W29XiUF+DkREIwjT2dqrcnXyxdWHQaUsxA6iYKteTpL9F81/w
EQdyBnT/jx7f9ff/xhsXOb8Bu5Fh4Mh0M7+bwMouj6mDjlboN5jZWLbqkRGZvj6B
5L4YxTg1uN600uEFpAjQ7Ru+XC9SybuKIaPWD+JkwEtk+urroHZ8aJAZONcM1qe9
56TLAYTpYikkxaMkWaLpSGLV8fbVMB1IoIvysJsdbtQyTB2vttFd8KheGDpa21xq
0SXZ/8zwbxiYeOCoG7KxQed5/Q/NrM2rHlK7sDjkXwwjxJ+xTNrm/gbk0dmAPO8R
wMyVUsBQUdM+XKziILQ5x42VOdGTXRQkzVbOAQCgOcb8mWaesyRcqwW1gTL1aLbb
qx6ctE/nuB9ujxGXr0SIz6EI/eOxILRRGoxwRKIFsUnzVDFxOK/PwHaUA4cEFl24
kh2qG/rBVBCkm6Pijmm4QDSfgnB6WlurxrYDQxQARAmKCwIZFGJHhpfNnu+vKdTE
kEpySUaRo1rNVjy/hivTjZlD87OOUECycmEi+f7gK8qMyG+qOOezeFs7z4A+EiZP
E4bZX09EhRAND35eK62q5OpPiOUhg7oVcLsa6pquRSzKvm4ofUA=
=39Kj
-----END PGP SIGNATURE-----