"redis":"7" redis-7.2.16-1.module+el9+1195+ab0a598a
エラータID: AXSA:2026-1844:01
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log.
Security Fix(es):
* redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373)
* redis: Redis: Denial of Service via Out-of-Bounds Read in Cluster Bus (CVE-2026-72568)
* redis: Redis: Arbitrary code execution via TLS pending-data list use-after-free (CVE-2026-81934)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-66373
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVE-2026-72568
REJECTED
CVE-2026-81934
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
Modularity name: "redis"
Stream name: "7"
Update packages.
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
N/A
SRPMS
- redis-7.2.16-1.module+el9+1195+ab0a598a.src.rpm
MD5: aed36516b30cb8447271697e0d493aad
SHA-256: a211d5566076ef787b4d4de8e4b3e8e96051b7c6f006831494c7f3540ceec6cc
Size: 4.46 MB
Asianux Server 9 for x86_64
- redis-7.2.16-1.module+el9+1195+ab0a598a.x86_64.rpm
MD5: 672e808ea194c696c6bab23c8ab00a02
SHA-256: f37ee2dddecbf1eff2f697ae3fe91cb5158a7b57484b123af52d15164f359c03
Size: 1.64 MB - redis-debugsource-7.2.16-1.module+el9+1195+ab0a598a.x86_64.rpm
MD5: f73d42b4939a4002ef7e7bca66f0d285
SHA-256: 1532c69d1a45d7d3f279787fedf0dd2ad60031e7557750f635c7113d36cceabe
Size: 1.54 MB - redis-devel-7.2.16-1.module+el9+1195+ab0a598a.x86_64.rpm
MD5: 50325d1e49487d2a05fa6758c49684b3
SHA-256: 0b16652cfaf096025eb911c09c245c9276311a8869433bd3428ea07b50157943
Size: 24.32 kB - redis-doc-7.2.16-1.module+el9+1195+ab0a598a.noarch.rpm
MD5: c7a37334126e496cfc9987bd3686c1ab
SHA-256: 78f4b0a341e485148be705a35774b9ce59829a90b4eb864e983bda2e28a85e8b
Size: 640.42 kB