megachangelog
Security8.6.5

Redis 8.6.5 Security Release

This release contains critical security fixes addressing use-after-free vulnerabilities in stream RESTORE payloads and RedisBloom that could lead to remote code execution, as well as a bug fix to prevent silent Cuckoo Filter data loss on failover.

SECURITY: There are security fixes in the release.

Security fixes

  • A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution
  • RedisBloom/RedisBloom#1046 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution

Bug fixes

securityrcestreamredisbloomreliability

Source: original entry ↗