megachangelog
Security8.6.3

8.6.3 Security and Bug Fixes

This release addresses critical security vulnerabilities including use-after-free and invalid memory access issues that could lead to remote code execution, plus numerous bug fixes affecting SUBSCRIBE commands, CONFIG SET, Lua scripts, and RediSearch operations.

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution
  • (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote Code Execution
  • (CVE-2026-23631) Lua Use-After-Free may lead to remote code execution
  • (CVE-2026-25588) Invalid memory access in RESTORE may lead to Remote Code Execution (Time Series)
  • (CVE-2026-25589) Invalid memory access in RESTORE may lead to Remote Code Execution (Probabilistic)

Bug fixes

Metrics

securityfixcvememoryredisearch

Source: original entry ↗