[Git][security-tracker-team/security-tracker][master] Update status for redis with CVE-2026-66373 and CVE-2026-25243 mapping

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 05:08:35 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
459956e2 by Salvatore Bonaccorso at 2026-09-25T06:07:49+02:00
Update status for redis with CVE-2026-66373 and CVE-2026-25243 mapping

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -75159,7 +75159,7 @@ CVE-2026-64257 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://git.kernel.org/linus/8986c932905ea508d66da421eb2eb6e676ace1fe (7.2-rc4)
 CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated attacke ...)
 	{DLA-4722-1}
-	- redis 5:8.0.6-3 (bug #1147422)
+	- redis <not-affected> (Incomplete fix for CVE-2026-25243 not applied)
 	NOTE: Fixed by: https://github.com/redis/redis/commit/4f62a8bf15c634187d8a87d874f8988032f90b6c (8.6.5)
 	NOTE: Fixed by: https://github.com/redis/redis/commit/04292292f2f5c180322292007a599a700611ebaf (7.2.15)
 	NOTE: fixed by: https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3 (6.2.23)
@@ -139318,6 +139318,8 @@ CVE-2026-25243 (Redis is an in-memory data structure store. In versions of redis
 	NOTE: https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4
 	NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-25243-deep-dive
 	NOTE: Fixed by: https://github.com/redis/redis/commit/b9dde6fc25dec6191b18374335a076a7b31e3d02 (8.6.3)
+	NOTE: When fixing this issue make the fix complete with the followups for CVE-2026-66373 to
+	NOTE: open up CVE-2026-66373.
 	TODO: check redict and valkey
 CVE-2026-23631 (Redis is an in-memory data structure store. In all versions of redis-s ...)
 	{DLA-4682-1}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/459956e268a74eb0fc8aa82ff9e1ec49ecd762c1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/459956e268a74eb0fc8aa82ff9e1ec49ecd762c1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/ceee97ac/attachment.htm>


More information about the debian-security-tracker-commits mailing list