valkey-8.0.9-1.el9_8
エラータID: AXSA:2026-1342:03
リリース日:
2026/07/27 Monday - 17:18
題名:
valkey-8.0.9-1.el9_8
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Redis には、メモリ領域の解放後利用の問題があるため、リモートの
攻撃者により、任意のコードの実行を可能とする脆弱性が存在します。
(CVE-2026-23479)
- Redis には、メモリ領域の解放後利用の問題があるため、リモート
の攻撃者により、巧妙に細工された Lua スクリプトを介して、任意の
コードの実行を可能とする脆弱性が存在します。(CVE-2026-23631)
- Redis には、不正なメモリ領域へのアクセスを誘発する問題があるため、
リモートの攻撃者により、サービス拒否攻撃 (クラッシュの発生)、および
任意のコードの実行を可能とする脆弱性が存在します。(CVE-2026-25243)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-23479
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
CVE-2026-23631
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
CVE-2026-25243
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3.
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3.
追加情報:
N/A
ダウンロード:
SRPMS
- valkey-8.0.9-1.el9_8.src.rpm
MD5: a6458996a2b346c5a66f34db6e4c089b
SHA-256: f304b1727e585732cbdacae80e18c946dfc0ced4c74595378f88321b348d40e5
Size: 3.50 MB
Asianux Server 9 for x86_64
- valkey-8.0.9-1.el9_8.x86_64.rpm
MD5: 21da8d45804c09bb998b2701e36643e9
SHA-256: 93d1a42658238e5e9c7e3ee369bca74711dfad15ba85a3af4bee889969464f43
Size: 1.60 MB - valkey-devel-8.0.9-1.el9_8.x86_64.rpm
MD5: fed2d52d8cf051e504bb1d5d628c86f9
SHA-256: 1590e7cba3e7db03750520f6d7afb2e7493505cf628d0a455f9e9b2f64709d16
Size: 25.77 kB