megachangelog
Security8.8.1

Security fix for RedisBloom and TDigest RESTORE payloads

A security vulnerability in RedisBloom and TDigest where crafted RESTORE payloads could trigger out-of-bounds writes has been fixed, preventing potential remote code execution.

SECURITY: There is a security fix in the release.

Security fixes

  • RedisBloom/RedisBloom#1044 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution
securityredisbloomtdigestrce

Source: original entry ↗