redis:7 security update
エラータID: AXSA:2026-1347:01
リリース日:
2026/07/27 Monday - 19:15
題名:
redis:7 security update
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Redis には、メモリ領域の解放後利用の問題があるため、リモートの
攻撃者により、任意のコードの実行を可能とする脆弱性が存在します。
(CVE-2026-23479)
- Redis には、メモリ領域の解放後利用の問題があるため、リモートの
攻撃者により、巧妙に細工された Lua スクリプトを介して、任意のコード
の実行を可能とする脆弱性が存在します。(CVE-2026-23631)
- Redis には、不正なメモリ領域へのアクセスを誘発する問題があるため、
リモートの攻撃者により、サービス拒否攻撃 (クラッシュの発生)、および
任意のコードの実行を可能とする脆弱性が存在します。(CVE-2026-25243)
Modularity name: redis
Stream name: 7
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-23479
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
CVE-2026-23631
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
CVE-2026-25243
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3.
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3.
追加情報:
N/A
ダウンロード:
SRPMS
- redis-7.2.14-1.module+el9+1165+6490c550.src.rpm
MD5: fcfe6e6dde8084a51db4b3b0c819445b
SHA-256: 2d29fa3d4456d6ce772d7e335104fe462c9bcb97189b9a69f6692a209d34a1eb
Size: 4.45 MB
Asianux Server 9 for x86_64
- redis-7.2.14-1.module+el9+1165+6490c550.x86_64.rpm
MD5: b2be0b592b27ea8bc21efb82a303c1b5
SHA-256: ba3ce45954515d30f55076a719361239df2271bacec529b37afb12e0c09aad0a
Size: 1.64 MB - redis-debugsource-7.2.14-1.module+el9+1165+6490c550.x86_64.rpm
MD5: bf74655281a99aac95aa8874efe12361
SHA-256: 3aaadeaf38b9fc2624eb8555db66d2924b89795b6e23f4f80b241d74834fecf6
Size: 1.54 MB - redis-devel-7.2.14-1.module+el9+1165+6490c550.x86_64.rpm
MD5: 9cc0fcdb86f4ca2eb9b0dcb72b01849b
SHA-256: 596b50f564bbf6d6306352d165921dd357d86a106e512a6891f128520c1e3e6b
Size: 24.20 kB - redis-doc-7.2.14-1.module+el9+1165+6490c550.noarch.rpm
MD5: 8ffb75385744310ce864c821f4a8270d
SHA-256: 7eba372ee7fe14d6809a1bf279bc26b8e10bece40600c7621da19a60de1b8a34
Size: 640.38 kB