Home / mailingsPDF  

[SECURITY] [DSA 6538-1] redis security update

Posted on 02 October 2026
Debian Security Advisory

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6538-1 security@debian.org
https://www.debian.org/security/ Aron Xu
October 02, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : redis
CVE ID : CVE-2026-23479 CVE-2026-23631 CVE-2026-25243 CVE-2026-81934
Debian Bug : 1147421 1147422 1147423

Multiple vulnerabilities were discovered in Redis, a persistent key-value
database, which could result in denial of service or the execution of
arbitrary code.

This update also includes fixes for several related issues that have not
been assigned CVE identifiers: ACL key permission checks for SORT,
GEORADIUS, GEORADIUSBYMEMBER, XREAD and XREADGROUP could be bypassed; an
out-of-bounds read during ACL key extraction for KEYNUM commands invoked
with the wrong arity; missing validation of slot information when loading
RDB files; a use-after-free in the blocked client list; an out-of-bounds
read in HGETEX; and an integer overflow in the HyperLogLog hash function.

Additionally, CVE-2026-66373 addresses an incomplete fix for CVE-2026-25243.
Because that interim fix was never released on its own in Debian stable,
it is therefore not referenced in the CVE ID list above. This update
incorporates the comprehensive fix covering both issues.

For the stable distribution (trixie), these problems have been fixed in
version 5:8.0.2-3+deb13u3.

We recommend that you upgrade your redis packages.

For the detailed security status of redis please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/redis

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP