Security8.6.5
Redis 8.6.5 Security Release
This release contains critical security fixes addressing use-after-free vulnerabilities in stream RESTORE payloads and RedisBloom that could lead to remote code execution, as well as a bug fix to prevent silent Cuckoo Filter data loss on failover.
SECURITY: There are security fixes in the release.
Security fixes
- A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution
- RedisBloom/RedisBloom#1046 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution
Bug fixes
- RedisBloom/RedisBloom#1021 Replicate
CF.LOADCHUNKdata chunks to prevent silent Cuckoo Filter data loss on failover
securityrcestreamredisbloomreliability
Source: original entry ↗