-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4682-1                [email protected]
https://www.debian.org/lts/security/                           Chris Lamb
July 13, 2026                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : redis
Version        : 5:7.0.15-1~deb12u8
CVE ID         : CVE-2026-23631 CVE-2026-25243

It was discovered that there were two issues in Redis, the in-memory
key/value database:

CVE-2026-23631

    An authenticated attacker could have exploited the master-replica
    synchronization mechanism to trigger a use-after-free on replicas
    where "replica-read-only" is disabled (or could be disabled),
    which may have led to remote code execution. Installations that
    prevent users from executing Lua scripts were unaffected.

CVE-2026-25243

    The RESTORE command did not properly validate serialized values.
    An authenticated attacker with permission to execute RESTORE
    could have suppled a crafted serialized payload that triggers
    invalid memory access and this could have led to remote code
    execution.

For Debian 12 bookworm, these problems have been fixed in version
5:7.0.15-1~deb12u8.

We recommend that you upgrade your redis packages.

For the detailed security status of redis please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/redis

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmpVal4ACgkQHpU+J9Qx
HljTTBAAp0Qw8EKHRdxbbWCRzbAFfyRM2II0PycLokclcvMLgop89SelpuGl4mge
oc40cTY/U5HgMQcpaZKQOMGSDmcqsJZQ3VZEPoNSiPq5t+kA5GjfqMzMzA0eI9Q/
e7dn6RGWPS0yYP0JisC4dX+TmHpcpg1j1fQ4CJMLhwkjlIv27K/4DDOa3rDACSHq
Ocm+HM/psMs5/5qLFzCMHXFCD8vt68VuLYBwpDwMYv+VUJJNAnt2hKHHLFhcjIdO
x/2p4DKkmZ+t8p1C7LNXMXv552RqCf2pGSs2Xzlh+3sswV9ctc/Z2vaybeKl1yH3
z1uiV2ySaXXPGOfEMrHzlUtdp2pY8bjnGIewgOPNaXfg6ms4xBmX3EOXc/E8XkyX
LgSf81SbpAjVXErcq/lgewTCFAJ66rNJefj9LZb4FFZEBHoIC/0TapuO6De/fuF+
xaUElnE4PdfLQF1FUk+Es4X/TYVySs+iXetqCUCYFnEvX4KpvnOoMDnTvr1ri0ul
mzVAh7A13veVKXM2yGCZ78L8sIJ/jnxF1/fhM8bJsQiBZDTaS1SfcNmfwFFBekmY
1r3NcCZWwJiQdWUUjL7i6ss/+49tSS3H+65mhMY1LtOrwXqZw1X7M5804XWbYBPI
25FRs+mYxVdg1RR691+FbuAHrUV6AMmYIn1JUln91oyohJ3N3mg=
=mGrP
-----END PGP SIGNATURE-----

Reply via email to