"redis":"6" redis-6.2.24-1.module+el8+2041+e977917f
エラータID: AXSA:2026-1841:01
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log.
Security Fix(es):
* redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373)
* redis: Redis: Arbitrary code execution via TLS pending-data list use-after-free (CVE-2026-81934)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-66373
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVE-2026-81934
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
Modularity name: "redis"
Stream name: "6"
Update packages.
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
N/A
SRPMS
- redis-6.2.24-1.module+el8+2041+e977917f.src.rpm
MD5: fea67cce5ff61de982c1cf14be58d407
SHA-256: 0054185b64e93b8e41fbee7a9b089338bb5bc9e52ea71020a9e41438877ffdbb
Size: 2.99 MB
Asianux Server 8 for x86_64
- redis-6.2.24-1.module+el8+2041+e977917f.x86_64.rpm
MD5: bca3e10986eb6f664fd2aa3ca3166475
SHA-256: caefde2c48584b6d189b786071d0091ff0c43de3391dfa4ce459421b2c800ba9
Size: 1.17 MB - redis-debugsource-6.2.24-1.module+el8+2041+e977917f.x86_64.rpm
MD5: 27b09bdbc7ed53927c3881af3b49b90e
SHA-256: 6182dcf4b29de19c40320d74f925fadeda23ba3a64357685765b65953657a0c1
Size: 1.34 MB - redis-devel-6.2.24-1.module+el8+2041+e977917f.x86_64.rpm
MD5: d0f3e5978eaf7aa2470c45931ec28377
SHA-256: 6baeedfb7ac412fe172ab01516113c3f1c090290305a8b581e31739c61e49016
Size: 30.59 kB - redis-doc-6.2.24-1.module+el8+2041+e977917f.noarch.rpm
MD5: 9128827f1ea69fa7fd902e6a79cd9bdc
SHA-256: ed40f54d53bdbed489a1f8b0bc1e1158868d0efed017fa3885613dd76702030f
Size: 493.06 kB