[Git][security-tracker-team/security-tracker][master] redis fixed in sid
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 22:40:54 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b3421b75 by Moritz Muehlenhoff at 2026-09-24T23:40:21+02:00
redis fixed in sid
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -6896,7 +6896,7 @@ CVE-2026-92927 (A vulnerability was found in SourceCodester Drug Recommendation
CVE-2026-92926 (A vulnerability has been found in code-projects Matrimonial System 1.0 ...)
NOT-FOR-US: code-projects
CVE-2026-92925 (A flaw was found in Redis community. The cluster bus packet parser, re ...)
- - redis <unfixed> (bug #1148265)
+ - redis 5:8.0.6-3 (bug #1148265)
NOTE: https://github.com/redis/redis/pull/15263
NOTE: Fixed by: https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523 (8.10-rc1)
TODO: check if redict affected
@@ -34778,7 +34778,7 @@ CVE-2026-82072 (Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72
- chromium 151.0.7922.71-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-81934 (Redis contains a use-after-free vulnerability in the 'tlsProcessPendin ...)
- - redis <unfixed> (bug #1147423)
+ - redis 5:8.0.6-3 (bug #1147423)
NOTE: https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834 (8.8.2)
CVE-2026-81931 (Unrestricted Upload of File with Dangerous Type in the product photo u ...)
NOT-FOR-US: Roskus Prospero Flow CRM
@@ -75159,7 +75159,7 @@ CVE-2026-64257 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://git.kernel.org/linus/8986c932905ea508d66da421eb2eb6e676ace1fe (7.2-rc4)
CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated attacke ...)
{DLA-4722-1}
- - redis <unfixed> (bug #1147422)
+ - redis 5:8.0.6-3 (bug #1147422)
NOTE: Fixed by: https://github.com/redis/redis/commit/4f62a8bf15c634187d8a87d874f8988032f90b6c (8.6.5)
NOTE: Fixed by: https://github.com/redis/redis/commit/04292292f2f5c180322292007a599a700611ebaf (7.2.15)
NOTE: fixed by: https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3 (6.2.23)
@@ -139314,7 +139314,7 @@ CVE-2026-25588 (RedisTimeSeries is a time-series module for Redis. In all versio
CVE-2026-25243 (Redis is an in-memory data structure store. In versions of redis-serve ...)
{DLA-4682-1}
[experimental] - redis 5:8.6.3-1
- - redis <unfixed> (bug #1147421)
+ - redis 5:8.0.6-3 (bug #1147421)
[bullseye] - redis <not-affected> (Vulnerable code not present; checks for dups introduced later)
NOTE: https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4
NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-25243-deep-dive
@@ -139323,7 +139323,7 @@ CVE-2026-25243 (Redis is an in-memory data structure store. In versions of redis
CVE-2026-23631 (Redis is an in-memory data structure store. In all versions of redis-s ...)
{DLA-4682-1}
[experimental] - redis 5:8.6.3-1
- - redis <unfixed> (bug #1147421)
+ - redis 5:8.0.6-3 (bug #1147421)
[bullseye] - redis <ignored> (Invasive to backport entire timedOut mechanism etc.)
NOTE: https://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826
NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-23631-dark-replica
@@ -139331,7 +139331,7 @@ CVE-2026-23631 (Redis is an in-memory data structure store. In all versions of r
TODO: check redict and valkey
CVE-2026-23479 (Redis is an in-memory data structure store. In redis-server from 7.2.0 ...)
[experimental] - redis 5:8.6.3-1
- - redis <unfixed> (bug #1147421)
+ - redis 5:8.0.6-3 (bug #1147421)
[bookworm] - redis <not-affected> (Vulnerable code not present)
[bullseye] - redis <not-affected> (Vulnerable code not present)
NOTE: https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3421b750caef8c6e101bdb1d94cb34ea725dad9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3421b750caef8c6e101bdb1d94cb34ea725dad9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/8539975b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list