-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 15 Sep 2026 00:52:10 +0800
Source: redis
Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym
Architecture: arm64
Version: 5:8.0.2-3+deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: arm64 Build Daemon (arm-ubc-02) <buildd_arm64-arm-ubc-02@buildd.debian.org>
Changed-By: Aron Xu <aron@debian.org>
Description:
 redis-sentinel - Persistent key-value database with network interface (monitoring)
 redis-server - Persistent key-value database with network interface
 redis-tools - Persistent key-value database with network interface (client)
Closes: 1147421 1147422 1147423
Changes:
 redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE
     command did not properly validate serialized values; an
     authenticated attacker able to run RESTORE could supply a crafted
     payload triggering invalid memory access and possibly remote code
     execution. (Closes: #1147421)
   * CVE-2026-23631: Lua use-after-free on replicas. An authenticated
     attacker could exploit the master-replica synchronization mechanism
     to trigger a use-after-free on replicas where replica-read-only is
     disabled, potentially leading to remote code execution.
     (Closes: #1147421)
   * CVE-2026-23479: Use-after-free in the unblock client flow. The error
     return from processCommandAndResetClient was not handled when re-
     executing a blocked command, allowing an authenticated attacker to
     trigger a use-after-free and possibly remote code execution.
     (Closes: #1147421)
   * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is
     shared by several consumers, an incomplete fix for CVE-2026-25243;
     deleting both consumers with XGROUP DELCONSUMER could lead to remote
     code execution. (Closes: #1147422)
   * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when
     handling the TLS pending-data list. A remote unauthenticated
     attacker may be able to execute arbitrary code with the privileges
     of the server. (Closes: #1147423)
   * Some important fixes upstream shipped as security fixes without CVE:
     - From 8.2.9: ACL key-permission bypass in SORT,
     GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv
     access during ACL key extraction for wrong-arity KEYNUM commands,
     out-of-range SLOT_INFO slot id in RDB loading causing memory corruption,
     and a use-after-free in handleClientsBlockedOnKey when reprocessing a
     command evicts another client blocked on the same key.
     - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the
     FIELDS option lacks its numfields argument, and an integer overflow in
     the HyperLogLog MurmurHash64A with entries over 2GB.
Checksums-Sha1:
 85470df23feca5c0c36a11a7d6f13329f6b0afc6 27320 redis-sentinel_8.0.2-3+deb13u3_arm64.deb
 80157f010f9688609346c021baa66c0e5391fe6a 67364 redis-server_8.0.2-3+deb13u3_arm64.deb
 269f6c882970ef64e7bfb83b76472be6c0001f29 4478776 redis-tools-dbgsym_8.0.2-3+deb13u3_arm64.deb
 38e9dc3a3134067a6ddca23faa998105ec1a6074 1149976 redis-tools_8.0.2-3+deb13u3_arm64.deb
 82c143a1a66fa1f46891dfcf4c743e312066d189 7534 redis_8.0.2-3+deb13u3_arm64-buildd.buildinfo
Checksums-Sha256:
 42be5b174ca5deebfaa6a3ea4a6b77b09360c4e8e20bae297067befc988d8204 27320 redis-sentinel_8.0.2-3+deb13u3_arm64.deb
 e638c371d228c1893508bc3dfc07c370e50df08d1f2b1b64ed40f15b4cf767c0 67364 redis-server_8.0.2-3+deb13u3_arm64.deb
 f73ed9097e54fdfab6d4b9093cc5bdb52347fb31973899e46f7e2d13d3c37b22 4478776 redis-tools-dbgsym_8.0.2-3+deb13u3_arm64.deb
 830bfd0aa739a4cfb1524df0958583eff395bfe2b7458fa06d0eef2fcdf5d272 1149976 redis-tools_8.0.2-3+deb13u3_arm64.deb
 d130b39d78d2a2c295da5a9062d79ee019b7960aa61f88a8316fd34c124bde43 7534 redis_8.0.2-3+deb13u3_arm64-buildd.buildinfo
Files:
 d4de3bf7a180e7560381504d3847c95d 27320 database optional redis-sentinel_8.0.2-3+deb13u3_arm64.deb
 da3422df3c54afab0bb72af4c7666395 67364 database optional redis-server_8.0.2-3+deb13u3_arm64.deb
 6ee8ef26946bfda07e7c9e8e7bf07cfd 4478776 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_arm64.deb
 f152dab3649e891c426e7c9f3e4d17a2 1149976 database optional redis-tools_8.0.2-3+deb13u3_arm64.deb
 3146bad7d95cd2d8655a404e8b7cb994 7534 database optional redis_8.0.2-3+deb13u3_arm64-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEJkN0BnKzGWWW6tS+G5VHrWJmwgcFAmq857IACgkQG5VHrWJm
wgdEGRAAqaj9GRyqx7+nrZqA9byeAH2WGz+kIldCy97q1xI+NmXRZs0nKaewlEge
/6vUG78MP321jmi2nCmv+nyq3lWw1gBfwJBD91nws57XgeaTn8hHHoUfKy3GpqT/
BWsPlkfuslVUqNtO63i3jNZjqNkX7rg1UmWszXlGywGa1gB81HuH9xF3bLj0EBOm
qCGTK/m5bkrILeDfFXlmpF0JPKQia3qTjLldYmdvH5TxCsu5L9NKWchVjfQrM9KD
VCXRKsWeGAY6IBGiPtnnk4MDsJxRI9abC/oZdUkJ2NIzaw2+PUFOtqW+RhDX7PsB
gao3ZTGdxeyoW1BUHbKzNp35strBVGfzffCeIy9Z20Yxj3m5IKLjaxKJSJ+o6azB
mlY33u7nCTPaF7ujZkZ28mZ9wmNcUHiAq436X3jI4mnep+ECZmZx+4lSLcLQyMe9
TE/YDU+0vO1cU6M7bLx8wYwPon3p1hdawh/jWZofOGn7ElL5TIAWSDFcZiThzgmK
IplvoGeDbFS0W3GEzIELUuxZNPijYfFGjcTlr7jCk7VWT0FoiWARn1yB0HnGUm0u
S9ttSdESQ/nURQ6LlR/JXxilntK3PjUICZJDxsb/8gwXk76Km+WziQYJ42/1GhL+
77FRpajQiJj3Gafwba2DCU7cWbdPSn3uneyieuDCKwYA5f1bPGc=
=dF/d
-----END PGP SIGNATURE-----
