"redis":"7" redis-7.2.14-1.module+el9+1165+6490c550

エラータID: AXSA:2026-1347:01

Release date: 
Monday, July 27, 2026 - 19:15
Subject: 
"redis":"7" redis-7.2.14-1.module+el9+1165+6490c550
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log.

Security Fix(es):

* redis: use-after-free in unblock client flow may allow remote code execution (CVE-2026-23479)
* redis: Remote code execution via use-after-free in Lua scripting (CVE-2026-23631)
* redis: RESTORE invalid memory access may allow remote code execution (CVE-2026-25243)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-23479
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
CVE-2026-23631
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
CVE-2026-25243
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3.

Modularity name: "redis"
Stream name: "7"

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. redis-7.2.14-1.module+el9+1165+6490c550.src.rpm
    MD5: fcfe6e6dde8084a51db4b3b0c819445b
    SHA-256: 2d29fa3d4456d6ce772d7e335104fe462c9bcb97189b9a69f6692a209d34a1eb
    Size: 4.45 MB

Asianux Server 9 for x86_64
  1. redis-7.2.14-1.module+el9+1165+6490c550.x86_64.rpm
    MD5: b2be0b592b27ea8bc21efb82a303c1b5
    SHA-256: ba3ce45954515d30f55076a719361239df2271bacec529b37afb12e0c09aad0a
    Size: 1.64 MB
  2. redis-debugsource-7.2.14-1.module+el9+1165+6490c550.x86_64.rpm
    MD5: bf74655281a99aac95aa8874efe12361
    SHA-256: 3aaadeaf38b9fc2624eb8555db66d2924b89795b6e23f4f80b241d74834fecf6
    Size: 1.54 MB
  3. redis-devel-7.2.14-1.module+el9+1165+6490c550.x86_64.rpm
    MD5: 9cc0fcdb86f4ca2eb9b0dcb72b01849b
    SHA-256: 596b50f564bbf6d6306352d165921dd357d86a106e512a6891f128520c1e3e6b
    Size: 24.20 kB
  4. redis-doc-7.2.14-1.module+el9+1165+6490c550.noarch.rpm
    MD5: 8ffb75385744310ce864c821f4a8270d
    SHA-256: 7eba372ee7fe14d6809a1bf279bc26b8e10bece40600c7621da19a60de1b8a34
    Size: 640.38 kB