Release date:
2026-08-25 17:33:48 UTC
Description:
* SECURITY UPDATE: Double free via stream RDB payload with a shared NACK
- debian/patches/CVE-2026-66373.patch: reject the payload in rdbLoadObject()
when a global PEL entry already has a consumer assigned, preventing two
consumers from referencing one streamNACK and double freeing it when both
are removed with XGROUP DELCONSUMER
- CVE-2026-66373
Updated packages:
-
redis7_7.0.15-1~bookworm+tuxcare.els9_all.deb
sha:9a832f9b7b2a116c48d235e7ebbb48049d37d7da
-
redis7-sentinel_7.0.15-1~bookworm+tuxcare.els9_amd64.deb
sha:ea9bb7e4bc469ec57b67ddfadb254d331658df1c
-
redis7-server_7.0.15-1~bookworm+tuxcare.els9_amd64.deb
sha:0aae51316f7537c9fcc1062eb97dc3ab84b33bad
-
redis7-tools_7.0.15-1~bookworm+tuxcare.els9_amd64.deb
sha:86d97307e4e8d70de824f99ad4a385194598a42c
-
redis7_7.0.15-1~bookworm+tuxcare.els9_all.deb
sha:9a832f9b7b2a116c48d235e7ebbb48049d37d7da
-
redis7-sentinel_7.0.15-1~bookworm+tuxcare.els9_arm64.deb
sha:b970d8b9a0036a8751e61a96ada93df0571ab0d2
-
redis7-server_7.0.15-1~bookworm+tuxcare.els9_arm64.deb
sha:83d14bd253323a949b362154ec68132b5ffcb76f
-
redis7-tools_7.0.15-1~bookworm+tuxcare.els9_arm64.deb
sha:db3ebabe25e26835fc3608fb2831b290fc6b8da0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.