megachangelog
Security7.4.10

Security fix for stream RESTORE payload vulnerability

Fixed a critical security vulnerability where a crafted stream RESTORE payload could cause two consumers to share the same NACK, leading to a use-after-free condition that may result in Remote Code Execution.

Update urgency: SECURITY: There is a security fix in the release.

Security fixes

  • A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution
securitystreamsrcememory-safety

Source: original entry ↗