-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 15 Sep 2026 00:52:10 +0800
Source: redis
Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym
Architecture: i386
Version: 5:8.0.2-3+deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: i386 Build Daemon (x86-grnet-01) <buildd_amd64-x86-grnet-01@buildd.debian.org>
Changed-By: Aron Xu <aron@debian.org>
Description:
 redis-sentinel - Persistent key-value database with network interface (monitoring)
 redis-server - Persistent key-value database with network interface
 redis-tools - Persistent key-value database with network interface (client)
Closes: 1147421 1147422 1147423
Changes:
 redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE
     command did not properly validate serialized values; an
     authenticated attacker able to run RESTORE could supply a crafted
     payload triggering invalid memory access and possibly remote code
     execution. (Closes: #1147421)
   * CVE-2026-23631: Lua use-after-free on replicas. An authenticated
     attacker could exploit the master-replica synchronization mechanism
     to trigger a use-after-free on replicas where replica-read-only is
     disabled, potentially leading to remote code execution.
     (Closes: #1147421)
   * CVE-2026-23479: Use-after-free in the unblock client flow. The error
     return from processCommandAndResetClient was not handled when re-
     executing a blocked command, allowing an authenticated attacker to
     trigger a use-after-free and possibly remote code execution.
     (Closes: #1147421)
   * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is
     shared by several consumers, an incomplete fix for CVE-2026-25243;
     deleting both consumers with XGROUP DELCONSUMER could lead to remote
     code execution. (Closes: #1147422)
   * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when
     handling the TLS pending-data list. A remote unauthenticated
     attacker may be able to execute arbitrary code with the privileges
     of the server. (Closes: #1147423)
   * Some important fixes upstream shipped as security fixes without CVE:
     - From 8.2.9: ACL key-permission bypass in SORT,
     GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv
     access during ACL key extraction for wrong-arity KEYNUM commands,
     out-of-range SLOT_INFO slot id in RDB loading causing memory corruption,
     and a use-after-free in handleClientsBlockedOnKey when reprocessing a
     command evicts another client blocked on the same key.
     - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the
     FIELDS option lacks its numfields argument, and an integer overflow in
     the HyperLogLog MurmurHash64A with entries over 2GB.
Checksums-Sha1:
 7504edb6f2c8c8bb5f90350c9eb58cfbde725f6e 27320 redis-sentinel_8.0.2-3+deb13u3_i386.deb
 bb9dada2ead2e7ac4a5b877f952ed8250c78ad49 67364 redis-server_8.0.2-3+deb13u3_i386.deb
 439263eff2d0e03fbfe4b30b7cb87e34bdd85a3e 4171096 redis-tools-dbgsym_8.0.2-3+deb13u3_i386.deb
 f3910420e93076161539a5c5b7811ba21bca3e62 1263368 redis-tools_8.0.2-3+deb13u3_i386.deb
 449beb6ee64a545de8f10cca80f05c0f75b56f99 7445 redis_8.0.2-3+deb13u3_i386-buildd.buildinfo
Checksums-Sha256:
 07791fcaf46d4d3f0c69b8b5d5aaf253814970199f19e0439c8a234ae92696bc 27320 redis-sentinel_8.0.2-3+deb13u3_i386.deb
 c72b5eb116ef8c8b5419a0ff773f0d054b7bcaa95bc549582bbc767b05da5555 67364 redis-server_8.0.2-3+deb13u3_i386.deb
 0cca390294357549243d34200550617c1fa933873d74a1758d43ae2d6cf57c75 4171096 redis-tools-dbgsym_8.0.2-3+deb13u3_i386.deb
 f262fb65e8f106c2c2c03e87018c076e4d4bb36610de2a9dc5d55fd9aa0c9f53 1263368 redis-tools_8.0.2-3+deb13u3_i386.deb
 4f4ba4cc2b13577d58c5cd46f934e3eb91ae0749135ed45b1bd23dfd73047cdf 7445 redis_8.0.2-3+deb13u3_i386-buildd.buildinfo
Files:
 237d3b0e60db7a8f58fc3c277242935a 27320 database optional redis-sentinel_8.0.2-3+deb13u3_i386.deb
 4cee5e561a0e666e62d9899d2ac97c6f 67364 database optional redis-server_8.0.2-3+deb13u3_i386.deb
 d943d36bbf788f74a4478e56bf66dea3 4171096 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_i386.deb
 e8896884bd1bde54f6d2acbe8da950e6 1263368 database optional redis-tools_8.0.2-3+deb13u3_i386.deb
 01fdb395e989667a10acd4c765dd0fef 7445 database optional redis_8.0.2-3+deb13u3_i386-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmq86ekACgkQf2INRiCd
aWIv9g/+MbbDLVYOEj0xZv3Iam6LDvvgVV/qa3V/lpfmxliTR1bRNgRmavJ2ceP2
Wxnvv1bhVZVbVKkggQN0iizcV/OAdqmdqRLYUZ5M8YiVGZX7OSKAjP5yYmYv27Uk
zx4MclHC4LItwyt/ck4ux4ZZfv7JbsZqCbzmWFCSL3hf4m9vS2qGIWQlsh+NeQFA
VpdZZR5B8mwlup8Bcygb3uvE/lqq7/EwYQo3iTZzVDW/cAgAs5ddp9T6HSTAGSbK
k7p/HfGCuQMF4aJ0IYNiUinG8zzPjZDWqQIYe1I7vczEt3SU5unRhFfkL9fq46A3
2HNxnhehd/w0+vFxwmo0KA7SSTVyU033kQ3MNo2X0jqLL4FdZwL1xAwsHeKG4qB5
SUTLRoBTSz33x4HBJMPVioDtFS0hIEkSpzlf4EcAMQ9cZGMYbMqpjfpvuX0H33Y0
XNucQ9i7+bWoEWEBTE/gPRY+hJaizlIWyk7azZNQihClReFd0XH3AUwwh2DRNYIl
nZjbDveW4rUpSlKwzGSwdvS2LT09OQMbTG/+BYoYKyXu42tam5wi6vQNO5CaqCCN
RTCNdF0JNZc2QuNUEeN6j2dasrZdwauY4zmlv26N/xiWGFJIGzm6HYuZHBiSp36f
mp/ir8d9tRTxaHpNwEN8j9np0RtH29TULTmsf/k63GBUqIaYckA=
=8LCU
-----END PGP SIGNATURE-----
