UbuntuUpdates.org

Package "redis-server"

Name: redis-server

Description:

Persistent key-value database with network interface

Latest version: 5:8.0.5-1ubuntu0.1
Release: resolute (26.04)
Level: updates
Repository: universe
Head package: redis
Homepage: https://redis.io/

Links


Download "redis-server"


Other versions of "redis-server" in Resolute

Repository Area Version
base universe 5:8.0.5-1
security universe 5:8.0.5-1ubuntu0.1

Changelog

Version: 5:8.0.5-1ubuntu0.1 2026-10-07 15:39:34 UTC

redis (5:8.0.5-1ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Use-after-free vulnerability in tlsProcessPendingData()
    - debian/patches/CVE-2026-81934.patch: Fix use-after-free in
      tlsProcessPendingData() pending-list iteration (#1391) in src/tls.c.
    - CVE-2026-81934
  * SECURITY UPDATE: Potential out-of-bounds read and denial of service
    vulnerability due to missing null-terminator check
    - debian/patches/CVE-2026-92925.patch: Reject cluster bus PING
      extensions with missing null terminator (#15263) in src/cluster_legacy.c,
      tests/unit/cluster/hostnames.tcl.
    - CVE-2026-92925

 -- Hurman Thu, 01 Oct 2026 14:17:55 +0800

CVE-2026-81934 Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configur
CVE-2026-92925 A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate



About   -   Send Feedback to @ubuntu_updates