[Git][security-tracker-team/security-tracker][master] redis fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 22:40:54 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b3421b75 by Moritz Muehlenhoff at 2026-09-24T23:40:21+02:00
redis fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6896,7 +6896,7 @@ CVE-2026-92927 (A vulnerability was found in SourceCodester Drug Recommendation
 CVE-2026-92926 (A vulnerability has been found in code-projects Matrimonial System 1.0 ...)
 	NOT-FOR-US: code-projects
 CVE-2026-92925 (A flaw was found in Redis community. The cluster bus packet parser, re ...)
-	- redis <unfixed> (bug #1148265)
+	- redis 5:8.0.6-3 (bug #1148265)
 	NOTE: https://github.com/redis/redis/pull/15263
 	NOTE: Fixed by: https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523 (8.10-rc1)
 	TODO: check if redict affected
@@ -34778,7 +34778,7 @@ CVE-2026-82072 (Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-81934 (Redis contains a use-after-free vulnerability in the 'tlsProcessPendin ...)
-	- redis <unfixed> (bug #1147423)
+	- redis 5:8.0.6-3 (bug #1147423)
 	NOTE: https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834 (8.8.2)
 CVE-2026-81931 (Unrestricted Upload of File with Dangerous Type in the product photo u ...)
 	NOT-FOR-US: Roskus Prospero Flow CRM
@@ -75159,7 +75159,7 @@ CVE-2026-64257 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://git.kernel.org/linus/8986c932905ea508d66da421eb2eb6e676ace1fe (7.2-rc4)
 CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated attacke ...)
 	{DLA-4722-1}
-	- redis <unfixed> (bug #1147422)
+	- redis 5:8.0.6-3 (bug #1147422)
 	NOTE: Fixed by: https://github.com/redis/redis/commit/4f62a8bf15c634187d8a87d874f8988032f90b6c (8.6.5)
 	NOTE: Fixed by: https://github.com/redis/redis/commit/04292292f2f5c180322292007a599a700611ebaf (7.2.15)
 	NOTE: fixed by: https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3 (6.2.23)
@@ -139314,7 +139314,7 @@ CVE-2026-25588 (RedisTimeSeries is a time-series module for Redis. In all versio
 CVE-2026-25243 (Redis is an in-memory data structure store. In versions of redis-serve ...)
 	{DLA-4682-1}
 	[experimental] - redis 5:8.6.3-1
-	- redis <unfixed> (bug #1147421)
+	- redis 5:8.0.6-3 (bug #1147421)
 	[bullseye] - redis <not-affected> (Vulnerable code not present; checks for dups introduced later)
 	NOTE: https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4
 	NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-25243-deep-dive
@@ -139323,7 +139323,7 @@ CVE-2026-25243 (Redis is an in-memory data structure store. In versions of redis
 CVE-2026-23631 (Redis is an in-memory data structure store. In all versions of redis-s ...)
 	{DLA-4682-1}
 	[experimental] - redis 5:8.6.3-1
-	- redis <unfixed> (bug #1147421)
+	- redis 5:8.0.6-3 (bug #1147421)
 	[bullseye] - redis <ignored> (Invasive to backport entire timedOut mechanism etc.)
 	NOTE: https://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826
 	NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-23631-dark-replica
@@ -139331,7 +139331,7 @@ CVE-2026-23631 (Redis is an in-memory data structure store. In all versions of r
 	TODO: check redict and valkey
 CVE-2026-23479 (Redis is an in-memory data structure store. In redis-server from 7.2.0 ...)
 	[experimental] - redis 5:8.6.3-1
-	- redis <unfixed> (bug #1147421)
+	- redis 5:8.0.6-3 (bug #1147421)
 	[bookworm] - redis <not-affected> (Vulnerable code not present)
 	[bullseye] - redis <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3421b750caef8c6e101bdb1d94cb34ea725dad9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3421b750caef8c6e101bdb1d94cb34ea725dad9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/8539975b/attachment.htm>


More information about the debian-security-tracker-commits mailing list