[CLSA-2025:1766666643] Fix of 7 CVEs
Type:
security
Severity:
Critical
Release date:
2026-01-26 11:52:13 UTC
Description:
* SECURITY UPDATE: Lua cjson and cmsgpack integer overflow issues - debian/patches/CVE-2022-24834.patch: Fix integer overflows due to using wrong integer size in Lua libraries, add overflow checks and improve test coverage - CVE-2022-24834 * SECURITY UPDATE: potential denial-of-service due to unbounded pattern matching - debian/patches/CVE-2024-31228.patch: Add nesting limit protection against abusive glob-style pattern matching to prevent DoS attacks - CVE-2024-31228 * SECURITY UPDATE: Lua bit.tohex integer overflow - debian/patches/CVE-2024-31449.patch: Fix INT_MIN value handling in Lua bit.tohex function to prevent integer overflow - CVE-2024-31449 * SECURITY UPDATE: out of bounds write in HyperLogLog commands - debian/patches/CVE-2025-32023.patch: Add proper validation checks to prevent out of bounds write in HyperLogLog sparse representation - CVE-2025-32023 * SECURITY UPDATE: Lua script may lead to integer overflow and potential RCE - debian/patches/CVE-2025-46817.patch: Fix integer overflow in Lua table unpack and table access functions that could lead to remote code execution - CVE-2025-46817 * SECURITY UPDATE: Lua out-of-bound read vulnerability - debian/patches/CVE-2025-46819.patch: Fix out-of-bound read in Lua lexer when parsing long string escape sequences - CVE-2025-46819 * SECURITY UPDATE: Lua script may lead to remote code execution - debian/patches/CVE-2025-49844.patch: Fix improper handling of source name string in Lua parser to prevent remote code execution - CVE-2025-49844
Updated packages:
  • redis5_5.0.14-1~trixie+tuxcare.els2_all.deb
    sha:09115a2de2f30d7fdb1090de1778feab94289019
  • redis5-sentinel_5.0.14-1~trixie+tuxcare.els2_amd64.deb
    sha:2a367251a022663670014b0d82db8f78ad3a1dda
  • redis5-server_5.0.14-1~trixie+tuxcare.els2_amd64.deb
    sha:1c7d7e1649ed13ab8fb329458497082fa71ff914
  • redis5-tools_5.0.14-1~trixie+tuxcare.els2_amd64.deb
    sha:d1e461c513c149a1c42365e637cfee739aad71b9
  • redis5_5.0.14-1~trixie+tuxcare.els2_all.deb
    sha:2b1a94362b5c5aa820fb8f6c2730ee08330afcbb
  • redis5-sentinel_5.0.14-1~trixie+tuxcare.els2_arm64.deb
    sha:9a7d0e175b7c1b1783e8312c6ee146a2c206eb9f
  • redis5-server_5.0.14-1~trixie+tuxcare.els2_arm64.deb
    sha:0812eba1da6d6a408179fa2b5c46c8d2c6855523
  • redis5-tools_5.0.14-1~trixie+tuxcare.els2_arm64.deb
    sha:3ffe94126430302746ff17fc7ac0853db5e613ed
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.