[CLSA-2025:1766663735] Fix of 7 CVEs
Type:
security
Severity:
Critical
Release date:
2026-01-26 11:44:40 UTC
Description:
* SECURITY UPDATE: Lua cjson and cmsgpack integer overflow issues - debian/patches/CVE-2022-24834.patch: Fix integer overflows due to using wrong integer size in Lua libraries, add overflow checks and improve test coverage - CVE-2022-24834 * SECURITY UPDATE: potential denial-of-service due to unbounded pattern matching - debian/patches/CVE-2024-31228.patch: Add nesting limit protection against abusive glob-style pattern matching to prevent DoS attacks - CVE-2024-31228 * SECURITY UPDATE: Lua bit.tohex integer overflow - debian/patches/CVE-2024-31449.patch: Fix INT_MIN value handling in Lua bit.tohex function to prevent integer overflow - CVE-2024-31449 * SECURITY UPDATE: out of bounds write in HyperLogLog commands - debian/patches/CVE-2025-32023.patch: Add proper validation checks to prevent out of bounds write in HyperLogLog sparse representation - CVE-2025-32023 * SECURITY UPDATE: Lua script may lead to integer overflow and potential RCE - debian/patches/CVE-2025-46817.patch: Fix integer overflow in Lua table unpack and table access functions that could lead to remote code execution - CVE-2025-46817 * SECURITY UPDATE: Lua out-of-bound read vulnerability - debian/patches/CVE-2025-46819.patch: Fix out-of-bound read in Lua lexer when parsing long string escape sequences - CVE-2025-46819 * SECURITY UPDATE: Lua script may lead to remote code execution - debian/patches/CVE-2025-49844.patch: Fix improper handling of source name string in Lua parser to prevent remote code execution - CVE-2025-49844
Updated packages:
  • redis5_5.0.14-1~bookworm+tuxcare.els2_all.deb
    sha:a5d159d2fc417ee228e57f2c30a75989eed858cf
  • redis5-sentinel_5.0.14-1~bookworm+tuxcare.els2_amd64.deb
    sha:19e70d75db4eb07f470dda266f3fba04543cf0bd
  • redis5-server_5.0.14-1~bookworm+tuxcare.els2_amd64.deb
    sha:406edbff85b95517d158099d5dbe13b42d9376d6
  • redis5-tools_5.0.14-1~bookworm+tuxcare.els2_amd64.deb
    sha:fc88b729e7f8e9c14db216e346ed30a0f131be9e
  • redis5_5.0.14-1~bookworm+tuxcare.els2_all.deb
    sha:443e8686d3867eabf027622212447f2dc9223f64
  • redis5-sentinel_5.0.14-1~bookworm+tuxcare.els2_arm64.deb
    sha:5395aeda626e22090a0a5660da6694bd9174cf1c
  • redis5-server_5.0.14-1~bookworm+tuxcare.els2_arm64.deb
    sha:af954aae3d6c631995f79a4aa1dbd00263bdf843
  • redis5-tools_5.0.14-1~bookworm+tuxcare.els2_arm64.deb
    sha:c9d12c4ed366295a3e5a90c989cd78f0a342db0c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.