-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4722-1                [email protected]
https://www.debian.org/lts/security/                           Chris Lamb
August 06, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : redis
Version        : 5:5.0.14-1+deb10u11
CVE ID         : CVE-2026-66373

It was discovered that there was a potential remote-code
vulnerability in Redis, the key-value database.

CVE-2026-66373

    In the unusual case where an authenticated attacker could execute
    the `RESTORE` command, a malicious `RESTORE` payload could have
    resulted in a double-free.

For Debian 11 bullseye, this problem has been fixed in version
5:6.0.16-1+deb11u9.

For Debian 12 bookworm, this problem has been fixed in version
5:7.0.15-1~deb12u9.

We recommend that you upgrade your redis packages.

For the detailed security status of redis please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/redis

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmp0/tYACgkQHpU+J9Qx
HlhKYxAAjfJD3wh1mA3csPjsTDhNer/8P/Un83/mB9+e/ISi45GJjssx/CwR7jbG
RqhGnZ4fzH4NE3lkemH0riROCW/fYVvrIbMaXZYS0FW823Exa5akD1sl5oL/Yabb
UmDKKZQrSJVHuZp/U54lkAog3/g8oqkTqrhOVeC4uj6GNWvcprSCUmh7XhZkt2xe
kz++H3pyFFODBQ7oWKHKUlj7p3IT0WZOxp+ppmBBH/9fHQWpgF/T/zpyWeo2rXPs
LVebkgdKqsnQ4LPDRSLFpaU5r52LM4otCRic8bsMBsTEFADS2+2oVpKYWcNvkDSR
XEF4AtACfZct6JFn2NiyaeI1rAI75gHQ67Nr+/U4OIAas8RjiQYQxRMHLNjZDTGq
2m0HcaBZyAiP/NrIop262+Myajayul1hgTG4vrwLmfk/t0g4bajGqnvOtvYa6fyV
EWv9YG1tga3Rbrurye5K6yDjsoHA0ilyAai/aklWj15rRqT6u8JsJNeQlXMAE1IW
eKXakBjYJKN0JrFzjcwJrEtjZk+73b2Lls7eY/7/js8kuNrPRig1emYdrwKsW6Yr
h3w23htORga3ziuKItXFX1g9QYopWDz+ymmMQ+5DEMDRKTi6jUmzmCLvFYIUFJaL
Tmbuc6VQZQjUCiGY6gUokw2iPydwcY6rUL35/c9X6o8wjajCCkU=
=Ox28
-----END PGP SIGNATURE-----

Reply via email to