-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 15 Sep 2026 00:52:10 +0800
Source: redis
Binary: redis-sentinel redis-server redis-tools redis-tools-dbgsym
Architecture: armhf
Version: 5:8.0.2-3+deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: armhf Build Daemon (arm-conova-02) <buildd_arm64-arm-conova-02@buildd.debian.org>
Changed-By: Aron Xu <aron@debian.org>
Description:
 redis-sentinel - Persistent key-value database with network interface (monitoring)
 redis-server - Persistent key-value database with network interface
 redis-tools - Persistent key-value database with network interface (client)
Closes: 1147421 1147422 1147423
Changes:
 redis (5:8.0.2-3+deb13u3) trixie-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * CVE-2026-25243: Invalid memory access in RESTORE. The RESTORE
     command did not properly validate serialized values; an
     authenticated attacker able to run RESTORE could supply a crafted
     payload triggering invalid memory access and possibly remote code
     execution. (Closes: #1147421)
   * CVE-2026-23631: Lua use-after-free on replicas. An authenticated
     attacker could exploit the master-replica synchronization mechanism
     to trigger a use-after-free on replicas where replica-read-only is
     disabled, potentially leading to remote code execution.
     (Closes: #1147421)
   * CVE-2026-23479: Use-after-free in the unblock client flow. The error
     return from processCommandAndResetClient was not handled when re-
     executing a blocked command, allowing an authenticated attacker to
     trigger a use-after-free and possibly remote code execution.
     (Closes: #1147421)
   * CVE-2026-66373: Double free via RESTORE of a stream whose NACK is
     shared by several consumers, an incomplete fix for CVE-2026-25243;
     deleting both consumers with XGROUP DELCONSUMER could lead to remote
     code execution. (Closes: #1147422)
   * CVE-2026-81934: Use-after-free in tlsProcessPendingData() when
     handling the TLS pending-data list. A remote unauthenticated
     attacker may be able to execute arbitrary code with the privileges
     of the server. (Closes: #1147423)
   * Some important fixes upstream shipped as security fixes without CVE:
     - From 8.2.9: ACL key-permission bypass in SORT,
     GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP, out-of-bounds argv
     access during ACL key extraction for wrong-arity KEYNUM commands,
     out-of-range SLOT_INFO slot id in RDB loading causing memory corruption,
     and a use-after-free in handleClientsBlockedOnKey when reprocessing a
     command evicts another client blocked on the same key.
     - From 8.0.5: out-of-bounds argv read and crash in HGETEX when the
     FIELDS option lacks its numfields argument, and an integer overflow in
     the HyperLogLog MurmurHash64A with entries over 2GB.
Checksums-Sha1:
 4384def950bbefc8cdaa49f3bbca41dc2d98f097 27320 redis-sentinel_8.0.2-3+deb13u3_armhf.deb
 34d051bfceff3c97f8ecb30fd734fbc2effb05fc 67364 redis-server_8.0.2-3+deb13u3_armhf.deb
 9128c2c0a5cd2b3659c4cf067738024f5397d216 4150036 redis-tools-dbgsym_8.0.2-3+deb13u3_armhf.deb
 af96cdfed0e24cb4793cb28790f1467d77b0192a 1127840 redis-tools_8.0.2-3+deb13u3_armhf.deb
 265118516afe19025aaf5652499778e54931cf3b 7416 redis_8.0.2-3+deb13u3_armhf-buildd.buildinfo
Checksums-Sha256:
 1fa4d43fbd763f6b3f36d98004215564a7f8c59f26dcafdd6a2247e1e0428961 27320 redis-sentinel_8.0.2-3+deb13u3_armhf.deb
 9191d72a518b1a05dada6692c21babe281d872eceb68f56a49f8763e31965208 67364 redis-server_8.0.2-3+deb13u3_armhf.deb
 a53dd95214ff9a0826e6d0ab446bcec1b713b72699b6bed82edf3788672ee295 4150036 redis-tools-dbgsym_8.0.2-3+deb13u3_armhf.deb
 e95c8041c393ed2ad3c5932cef7bc4d10061d9ec5244ce9acbe1044cea2fdf3e 1127840 redis-tools_8.0.2-3+deb13u3_armhf.deb
 67ec1f2eae6cf4a2a1b7c989779764dbb77778a44c9bf3a32cdd987b54b3694c 7416 redis_8.0.2-3+deb13u3_armhf-buildd.buildinfo
Files:
 52dc6519eafd43dd8a5c4c0a4b1637e4 27320 database optional redis-sentinel_8.0.2-3+deb13u3_armhf.deb
 fddfc619a95812a1826b4cbf483e8b55 67364 database optional redis-server_8.0.2-3+deb13u3_armhf.deb
 9267c406558b6d1eae4ed4599e8ee3fd 4150036 debug optional redis-tools-dbgsym_8.0.2-3+deb13u3_armhf.deb
 8694e073113b3c6402aa87217fb9c6e1 1127840 database optional redis-tools_8.0.2-3+deb13u3_armhf.deb
 63f8531f84f8fc2233abc907f9789c02 7416 database optional redis_8.0.2-3+deb13u3_armhf-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEa5s+5E+WDkV2pQjwIyDMsRzdi8EFAmq86GcACgkQIyDMsRzd
i8H1+A/+McCRaQKUz/6ttuhOwvA/poauKH+3AG7MmuJSA6dVDN+aoBOh/6ZwxDMS
+gHOS2J2EnXN301gmoWl1+J70s43uO9TFZAtUowHpD6dv9X55BHKOtFhSiWA6w6l
p/+3FpznMMtCCJT/Kr2zTcR+0svL34lc9HGnk2dFxw3cWRCYPDxyWZq07+FSTUhn
eGfRcsO2LFwZ9HrATAjd8kDMihqWFlb7yRPwT0sUO8E9a2WxwijXhbGqqtE/m5hp
xJ/LR2zpmpt8RKvVY2Vg335/aAnQfJ/JZ6V4rPTRdmOTXAo02LRrD+HUBbz2hB63
jwcutoMT9F8Yf/YLau6zdhrpuIXaRKvLEJ3K04HULuH5Xderbe5k+1Y+TvZxSWJF
4/KaEdiQlaHdPPD8m+hK3Pgf8gtwJDhlSTldaGXXcCjC7r7rXnYocPz36yKqTDjJ
iOx9u85bNfSkXGG71k5jlryRJVbqPoF1R4SaD/I9ZDD2keusHL3QmTd8CYC5xBrR
IPyypCMy0/Ggr5ooDO0OIeSaHlXJgxUZZYMeXV+Lw+IbeG6h9bUU/5UENRNTB0En
bHAfMb0IADMgFGeQZvBDK8fOnaIuej756X6Zz1uQfkuHvjTJdJodMuAb5BDFjiji
CCcWnz8Fak5HpIvGUxLMMN/kC409zIYg9ol5LLJ1m7j5qbrBESI=
=HXYr
-----END PGP SIGNATURE-----
