Release date:
2026-09-28 09:37:30 UTC
Description:
* SECURITY UPDATE: Out-of-bounds read via cluster bus hostname extension
- debian/patches/CVE-2026-92925.patch: in clusterProcessPacket() reject
PING/PONG/MEET extensions shorter than their header, and reject a
hostname extension whose data is empty or not null-terminated, so a
crafted cluster bus packet can no longer make updateAnnouncedHostname()
read past the extension as a C string
- CVE-2026-92925
Updated packages:
-
redis7_7.0.15-1~trixie+tuxcare.els11_all.deb
sha:5f4522239d96877cd13ea0c9a3bcc34bf4ccc4f5
-
redis7-sentinel_7.0.15-1~trixie+tuxcare.els11_amd64.deb
sha:eafbc0c2588720d80a96a4357750f9c0209d1a87
-
redis7-server_7.0.15-1~trixie+tuxcare.els11_amd64.deb
sha:a9359449fe1d506cb5534dd7ee4dc40ba2c21b0f
-
redis7-tools_7.0.15-1~trixie+tuxcare.els11_amd64.deb
sha:e62f03dfc7449f501af656861c3ade676fc29022
-
redis7-sentinel_7.0.15-1~trixie+tuxcare.els11_arm64.deb
sha:53a8d0e9793761d32cce681720ba25e3713d4d9d
-
redis7-server_7.0.15-1~trixie+tuxcare.els11_arm64.deb
sha:8735a78670e511cbb5a3175398775bc319f140f6
-
redis7-tools_7.0.15-1~trixie+tuxcare.els11_arm64.deb
sha:aa128a33695a244d4a02bd15fc14c9a35c569e61
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.