[CLSA-2026:1790588238] Fix CVE(s): CVE-2026-92925
Type:
security
Severity:
Important
Release date:
2026-09-28 09:37:30 UTC
Description:
* SECURITY UPDATE: Out-of-bounds read via cluster bus hostname extension - debian/patches/CVE-2026-92925.patch: in clusterProcessPacket() reject PING/PONG/MEET extensions shorter than their header, and reject a hostname extension whose data is empty or not null-terminated, so a crafted cluster bus packet can no longer make updateAnnouncedHostname() read past the extension as a C string - CVE-2026-92925
CVEs fixed:
Updated packages:
  • redis7_7.0.15-1~trixie+tuxcare.els11_all.deb
    sha:5f4522239d96877cd13ea0c9a3bcc34bf4ccc4f5
  • redis7-sentinel_7.0.15-1~trixie+tuxcare.els11_amd64.deb
    sha:eafbc0c2588720d80a96a4357750f9c0209d1a87
  • redis7-server_7.0.15-1~trixie+tuxcare.els11_amd64.deb
    sha:a9359449fe1d506cb5534dd7ee4dc40ba2c21b0f
  • redis7-tools_7.0.15-1~trixie+tuxcare.els11_amd64.deb
    sha:e62f03dfc7449f501af656861c3ade676fc29022
  • redis7-sentinel_7.0.15-1~trixie+tuxcare.els11_arm64.deb
    sha:53a8d0e9793761d32cce681720ba25e3713d4d9d
  • redis7-server_7.0.15-1~trixie+tuxcare.els11_arm64.deb
    sha:8735a78670e511cbb5a3175398775bc319f140f6
  • redis7-tools_7.0.15-1~trixie+tuxcare.els11_arm64.deb
    sha:aa128a33695a244d4a02bd15fc14c9a35c569e61
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.