Release date:
2026-09-28 09:14:53 UTC
Description:
* SECURITY UPDATE: Out-of-bounds read via cluster bus hostname extension
- debian/patches/CVE-2026-92925.patch: in clusterProcessPacket() reject
PING/PONG/MEET extensions shorter than their header, and reject a
hostname extension whose data is empty or not null-terminated, so a
crafted cluster bus packet can no longer make updateAnnouncedHostname()
read past the extension as a C string
- CVE-2026-92925
Updated packages:
-
redis7_7.0.15-1~bookworm+tuxcare.els11_all.deb
sha:6b2b6a00b40d7da99313e524f0e6d7510b6bf885
-
redis7-sentinel_7.0.15-1~bookworm+tuxcare.els11_amd64.deb
sha:cd33b93cc3e8d1fcfb8614e0a9356cfaea068bed
-
redis7-server_7.0.15-1~bookworm+tuxcare.els11_amd64.deb
sha:96e7583bb629c8d6e99b5c54751bf0e876095c08
-
redis7-tools_7.0.15-1~bookworm+tuxcare.els11_amd64.deb
sha:1779a661cb620089892c4b4d6c5f69b2648d3c3e
-
redis7-sentinel_7.0.15-1~bookworm+tuxcare.els11_arm64.deb
sha:a151bcf5673ae380a6a7a2b3b7921a65ae895bac
-
redis7-server_7.0.15-1~bookworm+tuxcare.els11_arm64.deb
sha:25d961887df7b4f73fb66f04308b7d44ded3632c
-
redis7-tools_7.0.15-1~bookworm+tuxcare.els11_arm64.deb
sha:7a98a103518141f96f7f4eb335b769ff9f6431ff
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.