[CLSA-2026:1790586877] Fix CVE(s): CVE-2026-92925
Type:
security
Severity:
Important
Release date:
2026-09-28 09:14:53 UTC
Description:
* SECURITY UPDATE: Out-of-bounds read via cluster bus hostname extension - debian/patches/CVE-2026-92925.patch: in clusterProcessPacket() reject PING/PONG/MEET extensions shorter than their header, and reject a hostname extension whose data is empty or not null-terminated, so a crafted cluster bus packet can no longer make updateAnnouncedHostname() read past the extension as a C string - CVE-2026-92925
CVEs fixed:
Updated packages:
  • redis7_7.0.15-1~bookworm+tuxcare.els11_all.deb
    sha:6b2b6a00b40d7da99313e524f0e6d7510b6bf885
  • redis7-sentinel_7.0.15-1~bookworm+tuxcare.els11_amd64.deb
    sha:cd33b93cc3e8d1fcfb8614e0a9356cfaea068bed
  • redis7-server_7.0.15-1~bookworm+tuxcare.els11_amd64.deb
    sha:96e7583bb629c8d6e99b5c54751bf0e876095c08
  • redis7-tools_7.0.15-1~bookworm+tuxcare.els11_amd64.deb
    sha:1779a661cb620089892c4b4d6c5f69b2648d3c3e
  • redis7-sentinel_7.0.15-1~bookworm+tuxcare.els11_arm64.deb
    sha:a151bcf5673ae380a6a7a2b3b7921a65ae895bac
  • redis7-server_7.0.15-1~bookworm+tuxcare.els11_arm64.deb
    sha:25d961887df7b4f73fb66f04308b7d44ded3632c
  • redis7-tools_7.0.15-1~bookworm+tuxcare.els11_arm64.deb
    sha:7a98a103518141f96f7f4eb335b769ff9f6431ff
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.