[CLSA-2026:1787678764] Fix CVE(s): CVE-2026-66373
Type:
security
Severity:
Important
Release date:
2026-08-25 17:26:15 UTC
Description:
* SECURITY UPDATE: Double free via stream RDB payload with a shared NACK - debian/patches/CVE-2026-66373.patch: reject the payload in rdbLoadObject() when a global PEL entry already has a consumer assigned, preventing two consumers from referencing one streamNACK and double freeing it when both are removed with XGROUP DELCONSUMER - CVE-2026-66373
CVEs fixed:
Updated packages:
  • redis7_7.0.15-1~trixie+tuxcare.els9_all.deb
    sha:1d7f36b880c1c8eed047103ecd69cd381f5d6a72
  • redis7-sentinel_7.0.15-1~trixie+tuxcare.els9_amd64.deb
    sha:e73d1b15d21dee9edbcaa957b2a8c54065505f41
  • redis7-server_7.0.15-1~trixie+tuxcare.els9_amd64.deb
    sha:ff4073e3dcaac50361cc56a0fb70509c4ee1c489
  • redis7-tools_7.0.15-1~trixie+tuxcare.els9_amd64.deb
    sha:7aaf882845abd502810ef1f0fe2e89bdee229e66
  • redis7_7.0.15-1~trixie+tuxcare.els9_all.deb
    sha:1d7f36b880c1c8eed047103ecd69cd381f5d6a72
  • redis7-sentinel_7.0.15-1~trixie+tuxcare.els9_arm64.deb
    sha:56485901c2c910d5fb41d61a5152ae1864d73ab4
  • redis7-server_7.0.15-1~trixie+tuxcare.els9_arm64.deb
    sha:af86d562ae7e37b13e4fa54f3eb214fd10df8014
  • redis7-tools_7.0.15-1~trixie+tuxcare.els9_arm64.deb
    sha:32c44f52296abfe79d18b8059c19f8c840d7df26
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.