megachangelog
Security8.2.8

Redis 8.2.8 Security Release

This release addresses critical security vulnerabilities including a use-after-free issue in stream consumer group restoration that could lead to remote code execution, and out-of-bounds write vulnerabilities in RedisBloom and TDigest. Also fixes a bug preventing Cuckoo Filter data replication on failover.

SECURITY: There are security fixes in the release.

Security fixes

  • Use-after-free when loading a stream consumer group via RESTORE may lead to Remote Code Execution
  • RedisBloom/RedisBloom#1041 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution

Bug fixes

securityrceblosumstabilityreplication

Source: original entry ↗