Zum Inhalt springen

Redis Release Notes

23 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.10.2: Sicherheitslücken und Abstürze behoben

Redis Open Source 8.10.2 behebt Sicherheitslücken: Per ACL entzogene Key-Rechte gelten nun auch für in Transaktionen eingereihte Befehle, neue Option cluster-bus-port-protected-mode und Startwarnung bei ungeschütztem Cluster-Bus-Port, außerdem Abstürze in TimeSeries, RedisSearch (KNN) und Vector Sets behoben.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • #15673 Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed
  • #15722 The cluster bus protocol has no authentication of its own unless tls-cluster is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new cluster-bus-port-protected-mode option (default no) makes refusing to run in that state an explicit choice: set it to yes and the node starts only when tls-cluster authenticates the bus
  • TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload
  • RedisSearch: KNN queries on indexes with very long vector field names could cause the server to crash
  • Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.8.3: ACL-Sicherheitslücken und Abstürze behoben

Redis Open Source 8.8.3 behebt Sicherheitslücken bei ACL-Rechten in Transaktionen, führt cluster-bus-port-protected-mode samt Startwarnung für ungeschützte Cluster-Bus-Ports ein und beseitigt Abstürze in TimeSeries und Vector Sets.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • #15673 Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed
  • #15722 The cluster bus protocol has no authentication of its own unless tls-cluster is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new cluster-bus-port-protected-mode option (default no) makes refusing to run in that state an explicit choice: set it to yes and the node starts only when tls-cluster authenticates the bus
  • TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload
  • Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.6.7: ACL-Sicherheitslücken und Abstürze behoben

Redis Open Source 8.6.7 behebt Sicherheitslücken bei ACL-Rechten in Transaktionen, führt cluster-bus-port-protected-mode samt Startwarnung für ungeschützte Cluster-Bus-Ports ein und beseitigt Abstürze in TimeSeries und Vector Sets.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • #15673 Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed
  • #15722 The cluster bus protocol has no authentication of its own unless tls-cluster is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new cluster-bus-port-protected-mode option (default no) makes refusing to run in that state an explicit choice: set it to yes and the node starts only when tls-cluster authenticates the bus
  • TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload
  • Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.4.7: ACL-Sicherheitslücken und Abstürze behoben

Redis Open Source 8.4.7 behebt Sicherheitslücken bei ACL-Rechten in Transaktionen, führt cluster-bus-port-protected-mode samt Startwarnung für ungeschützte Cluster-Bus-Ports ein und beseitigt Abstürze in TimeSeries und Vector Sets.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • #15673 Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed
  • #15722 The cluster bus protocol has no authentication of its own unless tls-cluster is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new cluster-bus-port-protected-mode option (default no) makes refusing to run in that state an explicit choice: set it to yes and the node starts only when tls-cluster authenticates the bus
  • TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload
  • Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.2.10: Cluster-Bus-Schutz und Absturzfixes

Redis Open Source 8.2.10 führt cluster-bus-port-protected-mode samt Startwarnung für ungeschützte Cluster-Bus-Ports ein und behebt Abstürze in TimeSeries und Vector Sets.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • #15722 The cluster bus protocol has no authentication of its own unless tls-cluster is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new cluster-bus-port-protected-mode option (default no) makes refusing to run in that state an explicit choice: set it to yes and the node starts only when tls-cluster authenticates the bus
  • TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload
  • Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.10.1: Mehrere Sicherheitslücken geschlossen

Redis Open Source 8.10.1 schließt mehrere Sicherheitslücken, darunter Speicherfehler beim RDB-Laden (mögliche Remote Code Execution), eine Umgehung der TLS-Client-Zertifikatsauthentifizierung sowie Fehler in CMSketch, TopK, Vector Sets und der Verwaltung blockierter Clients.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write
  • Out-of-bounds access in TopK heap cleanup path (MOD-15410)
  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
  • Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running
  • Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays
  • TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
  • #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.8.2: Mehrere Sicherheitslücken geschlossen

Redis Open Source 8.8.2 schließt mehrere Sicherheitslücken, darunter Speicherfehler beim RDB-Laden (mögliche Remote Code Execution), eine Umgehung der TLS-Zertifikatsauthentifizierung, ACL-Umgehungen bei SORT, GEORADIUS und XREAD sowie Fehler in Vector Sets, CMSketch und TopK.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write
  • Out-of-bounds access in TopK heap cleanup path (MOD-15410)
  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • #15478 ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
  • Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running
  • Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays
  • TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
  • #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.6.6: Mehrere Sicherheitslücken geschlossen

Redis Open Source 8.6.6 schließt mehrere Sicherheitslücken, darunter Speicherfehler beim RDB-Laden (mögliche Remote Code Execution), eine Umgehung der TLS-Zertifikatsauthentifizierung, ACL-Umgehungen bei SORT, GEORADIUS und XREAD sowie Fehler in Vector Sets, CMSketch und TopK.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write
  • Out-of-bounds access in TopK heap cleanup path (MOD-15410)
  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • #15478 ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
  • Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running
  • Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays
  • TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
  • #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.4.6: Mehrere Sicherheitslücken geschlossen

Redis Open Source 8.4.6 schließt mehrere Sicherheitslücken, darunter Speicherfehler beim RDB-Laden (mögliche Remote Code Execution), ACL-Umgehungen bei SORT, GEORADIUS und XREAD, einen Out-of-bounds-Zugriff bei der ACL-Prüfung von EVAL sowie Fehler in Vector Sets, CMSketch und TopK.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write
  • Out-of-bounds access in TopK heap cleanup path (MOD-15410)
  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • #15478 ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses
  • #14847 Out-of-bounds argv access during key extraction when checking ACL permissions of a KEYNUM keyspec command (e.g. EVAL) with wrong arity
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
  • Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running
  • Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays
  • #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.2.9: Mehrere Sicherheitslücken geschlossen

Redis Open Source 8.2.9 schließt mehrere Sicherheitslücken, darunter Speicherfehler beim RDB-Laden (mögliche Remote Code Execution), ACL-Umgehungen bei SORT, GEORADIUS und XREAD, einen Out-of-bounds-Zugriff bei der ACL-Prüfung von EVAL sowie Fehler in Vector Sets, CMSketch und TopK.

Security fixes

  • (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write
  • Out-of-bounds access in TopK heap cleanup path (MOD-15410)
  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • #15478 ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses
  • #14847 Out-of-bounds argv access during key extraction when checking ACL permissions of a KEYNUM keyspec command (e.g. EVAL) with wrong arity
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
  • Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running
  • Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays
  • #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 7.4.11: Sicherheitslücken in RDB, ACL und TLS behoben

Redis Open Source 7.4.11 schließt Sicherheitslücken, darunter ein Speicherfehler beim RDB-Laden (mögliche Remote Code Execution), ACL-Umgehungen bei SORT, GEORADIUS und XREAD, eine fehlerhafte ACL-Prüfung bei EVAL sowie Use-after-free-Fehler bei TLS und blockierten Clients.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • #15478 ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses
  • #14847 Out-of-bounds argv access during key extraction when checking ACL permissions of a KEYNUM keyspec command (e.g. EVAL) with wrong arity
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 7.2.16 schließt ACL- und Use-after-free-Lücken

Redis Open Source 7.2.16 schließt Sicherheitslücken wie ACL-Umgehungen bei SORT, GEORADIUS und XREAD, eine fehlerhafte ACL-Prüfung bei KEYNUM-Befehlen wie EVAL sowie Use-after-free-Fehler bei TLS und blockierten Clients.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses
  • Out-of-bounds argv access during key extraction when checking ACL permissions of a KEYNUM keyspec command (e.g. EVAL) with wrong arity
  • Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 6.2.24 behebt Use-after-free bei TLS

Redis Open Source 6.2.24 behebt einen Use-after-free-Fehler in der TLS-Liste ausstehender Daten, wenn ein Befehl eine andere wartende Verbindung schließt.

Update urgency: SECURITY: There is a security fix in the release.

Security fixes

  • Use-after-free in the TLS pending-data list when a command closes another pending connection

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.10.0: Compact Hashes und neue Befehle

Redis Open Source 8.10.0 ist allgemein verfügbar und bringt Compact Hashes, neue Befehle wie HIMPORT, LMOVEM, BLMOVEM, SUNIONCARD, SDIFFCARD, BACKUP, FT.ALIASLIST und mehrere TimeSeries-Befehle, TLS-Zertifikatsauthentifizierung zwischen Servern, neue XREAD-Argumente sowie Leistungsverbesserungen.

This is the General Availability release of Redis 8.10 in Redis Open Source.

Major changes compared to 8.8

  • Compact hashes - a new hash encoding that reduces memory usage by storing hash field names just once for keys that share a schema
  • New command: HIMPORT - high-throughput compact hash bulk insertion
  • TLS peer certificate-based server-to-server authentication
  • New commands: LMOVEM, BLMOVEM - move multiple elements between lists
  • New command: SUNIONCARD - get the cardinality of the union of multiple sets
  • New command: SDIFFCARD - get the cardinality of the difference between sets
  • New command: BACKUP - node-side implementation for backup and restore based on multi-part AOF (MP-AOF)
  • XREAD, XREADGROUP - new MAXCOUNT and MAXSIZE arguments to cap the cumulative reply entries and size
  • New command: FT.ALIASLIST - get all aliases for the index
  • Stemmer support for Malay and Tagalog languages
  • JSONPath extensions
  • New commands: TS.NRANGE, TS.NREVRANGE - Query a range across multiple time series; group results by timestamp
  • New command: TS.READ - optionally blocking read
  • New command: TS.QUERYLABELS - Get a list of labels and label-values
  • New command: TS.MRANGE, TS.MREVRANGE - new EXCLUDEEMPTY argument to exclude series with no reported samples
  • Performance improvements

Binary distributions

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.8.1 schließt RESTORE-Sicherheitslücke

Redis Open Source 8.8.1 behebt eine Sicherheitslücke, bei der manipulierte RESTORE-Payloads in RedisBloom und TDigest Out-of-bounds-Schreibzugriffe und potenziell Remote Code Execution auslösen konnten.

SECURITY: There is a security fix in the release.

Security fixes

  • RedisBloom/RedisBloom#1044 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.6.5 schließt RESTORE-Lücken, repliziert CF.LOADCHUNK

Redis Open Source 8.6.5 behebt Sicherheitslücken durch manipulierte Stream- und RedisBloom/TDigest-RESTORE-Payloads (mögliche Remote Code Execution) und repliziert CF.LOADCHUNK-Daten, um Datenverlust bei Cuckoo Filtern im Failover zu verhindern.

SECURITY: There are security fixes in the release.

Security fixes

  • A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution
  • RedisBloom/RedisBloom#1046 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution

Bug fixes

  • RedisBloom/RedisBloom#1021 Replicate CF.LOADCHUNK data chunks to prevent silent Cuckoo Filter data loss on failover

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.4.5 schließt RESTORE-Lücken, repliziert CF.LOADCHUNK

Redis Open Source 8.4.5 behebt Sicherheitslücken durch manipulierte Stream- und RedisBloom/TDigest-RESTORE-Payloads (mögliche Remote Code Execution) und repliziert CF.LOADCHUNK-Daten, um Datenverlust bei Cuckoo Filtern im Failover zu verhindern.

SECURITY: There are security fixes in the release.

Security fixes

  • A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution
  • RedisBloom/RedisBloom#1039 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution

Bug fixes

  • RedisBloom/RedisBloom#1020 Replicate CF.LOADCHUNK data chunks to prevent silent Cuckoo Filter data loss on failover

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 8.2.8 schließt RESTORE-Lücken, repliziert CF.LOADCHUNK

Redis Open Source 8.2.8 behebt Sicherheitslücken durch manipulierte Stream- und RedisBloom/TDigest-RESTORE-Payloads (mögliche Remote Code Execution) und repliziert CF.LOADCHUNK-Daten, um Datenverlust bei Cuckoo Filtern im Failover zu verhindern.

SECURITY: There are security fixes in the release.

Security fixes

  • A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution
  • RedisBloom/RedisBloom#1041 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution

Bug fixes

  • RedisBloom/RedisBloom#1019 Replicate CF.LOADCHUNK data chunks to prevent silent Cuckoo Filter data loss on failover

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 7.4.10 behebt Stream-RESTORE-Sicherheitslücke

Redis Open Source 7.4.10 behebt eine Sicherheitslücke, bei der ein manipulierter Stream-RESTORE-Payload zu einem Use-after-free und möglicher Remote Code Execution führen konnte.

Update urgency: SECURITY: There is a security fix in the release.

Security fixes

  • A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Redis Os von Redis

Redis Open Source 7.2.15 behebt Stream-RESTORE-Sicherheitslücke

Redis Open Source 7.2.15 behebt eine Sicherheitslücke, bei der ein manipulierter Stream-RESTORE-Payload zu einem Use-after-free und möglicher Remote Code Execution führen konnte.

Update urgency: SECURITY: There is a security fix in the release.

Security fixes

  • A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution

Originalquelle(öffnet in neuem Tab)Problem melden