-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 15 Sep 2026 00:52:10 +0800
Source: redis
Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym
Architecture: amd64
Version: 5:8.0.2-3+deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) <buildd_amd64-x86-ubc-01@buildd.debian.org>
Changed-By: Aron Xu <aron@debian.org>
Description:
 redis-sentinel - Persistent key-value database with network interface (monitoring)
 redis-server - Persistent key-value database with network interface
 redis-tools - Persistent key-value database with network interface (client)
Closes: 1147421 1147422 1147423
Changes:
 redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE
     command did not properly validate serialized values; an
     authenticated attacker able to run RESTORE could supply a crafted
     payload triggering invalid memory access and possibly remote code
     execution. (Closes: #1147421)
   * CVE-2026-23631: Lua use-after-free on replicas. An authenticated
     attacker could exploit the master-replica synchronization mechanism
     to trigger a use-after-free on replicas where replica-read-only is
     disabled, potentially leading to remote code execution.
     (Closes: #1147421)
   * CVE-2026-23479: Use-after-free in the unblock client flow. The error
     return from processCommandAndResetClient was not handled when re-
     executing a blocked command, allowing an authenticated attacker to
     trigger a use-after-free and possibly remote code execution.
     (Closes: #1147421)
   * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is
     shared by several consumers, an incomplete fix for CVE-2026-25243;
     deleting both consumers with XGROUP DELCONSUMER could lead to remote
     code execution. (Closes: #1147422)
   * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when
     handling the TLS pending-data list. A remote unauthenticated
     attacker may be able to execute arbitrary code with the privileges
     of the server. (Closes: #1147423)
   * Some important fixes upstream shipped as security fixes without CVE:
     - From 8.2.9: ACL key-permission bypass in SORT,
     GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv
     access during ACL key extraction for wrong-arity KEYNUM commands,
     out-of-range SLOT_INFO slot id in RDB loading causing memory corruption,
     and a use-after-free in handleClientsBlockedOnKey when reprocessing a
     command evicts another client blocked on the same key.
     - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the
     FIELDS option lacks its numfields argument, and an integer overflow in
     the HyperLogLog MurmurHash64A with entries over 2GB.
Checksums-Sha1:
 8147e9e912bc1141949808bc99a8af57fcfb327b 27320 redis-sentinel_8.0.2-3+deb13u3_amd64.deb
 e86e15cf9ec82d8400a24232abeab3bd63b49f0d 67364 redis-server_8.0.2-3+deb13u3_amd64.deb
 cbd97c7ea09f576914ad56c63fbbe32ab931cb60 4535320 redis-tools-dbgsym_8.0.2-3+deb13u3_amd64.deb
 0e9df7ee04a61c7c0b7cc358c1bcdd96b7a38fc6 1247524 redis-tools_8.0.2-3+deb13u3_amd64.deb
 1249d350ace5ca9082875a928c9a39e22793bfb7 7550 redis_8.0.2-3+deb13u3_amd64-buildd.buildinfo
Checksums-Sha256:
 54732ca16aababaae3c4cb0dd1f6505993fd69ec207ccc19b2276f1e10e65804 27320 redis-sentinel_8.0.2-3+deb13u3_amd64.deb
 16b5435d05745503f29c8b4ced5bdce3e800ae5370d5f70e6519664d7515cb0f 67364 redis-server_8.0.2-3+deb13u3_amd64.deb
 8f753e4c89dc4d4cd89a19ef1ae81ab889d1226cc39f885fd45c00e9abab9640 4535320 redis-tools-dbgsym_8.0.2-3+deb13u3_amd64.deb
 ca91969383b5e9ea7f278dde513e2bc444914961e19e7d94cda7745a95f6686a 1247524 redis-tools_8.0.2-3+deb13u3_amd64.deb
 d1fe67890f3b31c7881601f6f7e66b68e4aae1feb656fbca8d9a25f7da0a1e12 7550 redis_8.0.2-3+deb13u3_amd64-buildd.buildinfo
Files:
 5ceae37f14f54439ac8e9597459b4767 27320 database optional redis-sentinel_8.0.2-3+deb13u3_amd64.deb
 2f92e48919130efb1ac934c592b10624 67364 database optional redis-server_8.0.2-3+deb13u3_amd64.deb
 7b3e8b99de06443b83e655c470a2d671 4535320 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_amd64.deb
 967fc4dd2c9523855f6c3f1f636c933d 1247524 database optional redis-tools_8.0.2-3+deb13u3_amd64.deb
 351784a7f2d981d3436a98f6c9c6674a 7550 database optional redis_8.0.2-3+deb13u3_amd64-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmq856YACgkQTwt/65ON
6zfGmxAAh2/gyMUQcHj+x10TWtxZ7pmeo2XfUGBTMO+m+3BKZjsA1UHVHEB4zFFh
Rez1RiyrcybNLStSPpUkxVr5X7UnRu1gtB2dmbp7vbzuZfLl9f04S2rp3N4xf8ZH
Zf1zwZu8DgTD/Ap0Ar9V6dbrTE5IPogsT/3zw5fcYGTVQL3L1rmnUFwsXHS6/Wdh
CqpMMF0ngDZKABcCsWxAcCMKwaX3s+vGbcb1kU/LT0g0CKVwt6an9F6RD8pgX4NZ
FIPU8d0aPxGMbxwHCiWwWqeTwX+Lmf6byAjBhovjEPaDiqoGq27U+85pjDZsn18B
HFH5bNO8T4t/1WpAavxAgOFHAzsEyDkoPPg4sP7+HjtvMLiGtEqB14/twvHJQdXw
upTkafuBstyP/hBT+3Au60y7FZ9rbnJaGRD3w9ETMyGqe4ZUUJ/jUykAK//aXz9I
8p1rKBv4m5yW/cEb4YOHwXbQMq27veNA9sxcjZjN9H4JuE4ZAKDNeWXv43IAu1M1
Zhe2/vwyVIzv6AccmneFhJm5B1ZI+HoKCbeIVkm+LrBIWJDBqAYY2dJ9/9Tt7K8M
dYzoPt/EWA0x774HnzWbLwWR9WUqnwFfyaSjijbxWDrwy+H+OfKfJSaSpubfLkc+
0th30Wxa6C7i5D0GTNZTanCaJ7DtPqL0uyS+wDia4zXUkTGE1GM=
=6UTz
-----END PGP SIGNATURE-----
