Security8.6.7
Redis 8.6.7 Security and Stability Updates
This release addresses multiple security vulnerabilities including ACL permission bypass in transactions, unauthenticated cluster bus access, and crash issues in TimeSeries and Vector Sets modules. Security fixes cover transaction ACL enforcement, cluster bus authentication, and handling of malformed data structures.
Update urgency: SECURITY: There are security fixes in the release.
Security fixes
- #15673 Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed
- #15722 The cluster bus protocol has no authentication of its own unless
tls-clusteris enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the newcluster-bus-port-protected-modeoption (defaultno) makes refusing to run in that state an explicit choice: set it toyesand the node starts only whentls-clusterauthenticates the bus - TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload
- Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash
securityaclclustertimeseriesstability
Source: original entry ↗