[CLSA-2026:1787679218] Fix CVE(s): CVE-2026-66373
Type:
security
Severity:
Important
Release date:
2026-08-25 17:33:48 UTC
Description:
* SECURITY UPDATE: Double free via stream RDB payload with a shared NACK - debian/patches/CVE-2026-66373.patch: reject the payload in rdbLoadObject() when a global PEL entry already has a consumer assigned, preventing two consumers from referencing one streamNACK and double freeing it when both are removed with XGROUP DELCONSUMER - CVE-2026-66373
CVEs fixed:
Updated packages:
  • redis7_7.0.15-1~bookworm+tuxcare.els9_all.deb
    sha:9a832f9b7b2a116c48d235e7ebbb48049d37d7da
  • redis7-sentinel_7.0.15-1~bookworm+tuxcare.els9_amd64.deb
    sha:ea9bb7e4bc469ec57b67ddfadb254d331658df1c
  • redis7-server_7.0.15-1~bookworm+tuxcare.els9_amd64.deb
    sha:0aae51316f7537c9fcc1062eb97dc3ab84b33bad
  • redis7-tools_7.0.15-1~bookworm+tuxcare.els9_amd64.deb
    sha:86d97307e4e8d70de824f99ad4a385194598a42c
  • redis7_7.0.15-1~bookworm+tuxcare.els9_all.deb
    sha:9a832f9b7b2a116c48d235e7ebbb48049d37d7da
  • redis7-sentinel_7.0.15-1~bookworm+tuxcare.els9_arm64.deb
    sha:b970d8b9a0036a8751e61a96ada93df0571ab0d2
  • redis7-server_7.0.15-1~bookworm+tuxcare.els9_arm64.deb
    sha:83d14bd253323a949b362154ec68132b5ffcb76f
  • redis7-tools_7.0.15-1~bookworm+tuxcare.els9_arm64.deb
    sha:db3ebabe25e26835fc3608fb2831b290fc6b8da0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.