-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 00:52:10 +0800 Source: redis Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym Architecture: s390x Version: 5:8.0.2-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: s390x Build Daemon (zandonai) Changed-By: Aron Xu Description: redis-sentinel - Persistent key-value database with network interface (monitoring) redis-server - Persistent key-value database with network interface redis-tools - Persistent key-value database with network interface (client) Closes: 1147421 1147422 1147423 Changes: redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE command did not properly validate serialized values; an authenticated attacker able to run RESTORE could supply a crafted payload triggering invalid memory access and possibly remote code execution. (Closes: #1147421) * CVE-2026-23631: Lua use-after-free on replicas. An authenticated attacker could exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled, potentially leading to remote code execution. (Closes: #1147421) * CVE-2026-23479: Use-after-free in the unblock client flow. The error return from processCommandAndResetClient was not handled when re- executing a blocked command, allowing an authenticated attacker to trigger a use-after-free and possibly remote code execution. (Closes: #1147421) * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is shared by several consumers, an incomplete fix for CVE-2026-25243; deleting both consumers with XGROUP DELCONSUMER could lead to remote code execution. (Closes: #1147422) * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when handling the TLS pending-data list. A remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the server. (Closes: #1147423) * Some important fixes upstream shipped as security fixes without CVE: - From 8.2.9: ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv access during ACL key extraction for wrong-arity KEYNUM commands, out-of-range SLOT_INFO slot id in RDB loading causing memory corruption, and a use-after-free in handleClientsBlockedOnKey when reprocessing a command evicts another client blocked on the same key. - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the FIELDS option lacks its numfields argument, and an integer overflow in the HyperLogLog MurmurHash64A with entries over 2GB. Checksums-Sha1: b9fba664ecadc685603c782b4001e5c7649124e5 27320 redis-sentinel_8.0.2-3+deb13u3_s390x.deb 86b68365270707ec1c304af97f3a4244bac8a878 67364 redis-server_8.0.2-3+deb13u3_s390x.deb b8c06707650a6c3700c3584381a2acb7bd248f36 4201900 redis-tools-dbgsym_8.0.2-3+deb13u3_s390x.deb f6799b6c28421fc412b4cccc8e035197e538d3cd 1220288 redis-tools_8.0.2-3+deb13u3_s390x.deb 6e79eec33a216cae0be230951032a7d0483af76d 7412 redis_8.0.2-3+deb13u3_s390x-buildd.buildinfo Checksums-Sha256: 6cdc5b7303369e1ab65bac0539bae8674d2c21e0b3e3c93492a628a064bbf80a 27320 redis-sentinel_8.0.2-3+deb13u3_s390x.deb 8c097228043e0eeec88b14b41f808cf211d0a042240a76b3080ce176d9578ac9 67364 redis-server_8.0.2-3+deb13u3_s390x.deb 3bcc5d78808f1e3e9240f7ed61a56e4b12af18e333522ece44badd61d33591e5 4201900 redis-tools-dbgsym_8.0.2-3+deb13u3_s390x.deb c156418a23d03c51e0b1ef546d239eff5e24e11029a58d1aac77dadde795ce58 1220288 redis-tools_8.0.2-3+deb13u3_s390x.deb b0896411c8d9099e8da20f19f90d7333569cdb2f64fff13f757c84883700534b 7412 redis_8.0.2-3+deb13u3_s390x-buildd.buildinfo Files: 7b0d457ffeb17c49fb9a17305ee4b261 27320 database optional redis-sentinel_8.0.2-3+deb13u3_s390x.deb abc00397c142ed7bdd977d5fd8ac60a6 67364 database optional redis-server_8.0.2-3+deb13u3_s390x.deb f078b59d149e6c950e73f1df5030e5e1 4201900 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_s390x.deb 9e500b40cbb6c1ea7f8f34096a5f4992 1220288 database optional redis-tools_8.0.2-3+deb13u3_s390x.deb 6dcebefbea7aba52ae8e65eed0484da1 7412 database optional redis_8.0.2-3+deb13u3_s390x-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEENly2ANlpa4eeqnluvVOPI7pYNpgFAmq85YgACgkQvVOPI7pY NphiBxAAqGl490e5YhgLIyGkWcXJqeLVDt08bB4Hpc09GAWyPhJ14zUvdMUCZaIm GSbGFsd6ObaakYeZFZh2oNXUwyLRIUMVr+pH5ZVt8J0EnmF4DuEHJxcN+VeOBOaZ u+W/hccm90ilcI/wED3EjjDjjb9LbYHewPGUXWq5n0gz7zNAARvFIx+V8IFGtlGS mK2any853SzdyYQIPpj9RJ05qb2ZYCjW+iMuwLE84gNh+pq8wj2MjBYxADFW01lH yuX2fOObknk8mILVE/livWisGyWvJXlWPhpBL8ewvbIBvFi4jjk+xQzuEsowDySf CDaDi18HRe0zIzP9FlUhX3hujioCe/8GMH90bTP6skeb6xh0sKjxnMBxUefw7lWh 7a1YuHBPh1aW5+gHPz3T7UxNCK2nIDNHgWdR4ANnzjhJ6YPD/vSrxeEJwP/QzAFX evHNtwotZhWS0pdidPnWYlAXuBCa41zaCb+thwsXuZhNAlFpy95xEh1pss3SlU51 KVhxtt2ldWZUXuHYdqdsFM4+ZjB1eHGVMKNXevVbde+CpveYTtt/NdsJQe5+kpeE n+1nxwzqWvvyc/iWmxN/fzBb8mNqC0sSqzGjMkp7SO9nTeRw2T8daxIxuzg8VHrA PmeTJ2ZcmmFqC4iWqzAMGdx5moWhrUmv7qRI25uJLnb6uhrCHcY= =YSFh -----END PGP SIGNATURE-----