Security7.4.10
Security fix for stream RESTORE payload vulnerability
Fixed a critical security vulnerability where a crafted stream RESTORE payload could cause two consumers to share the same NACK, leading to a use-after-free condition that may result in Remote Code Execution.
Update urgency: SECURITY: There is a security fix in the release.
Security fixes
- A crafted stream
RESTOREpayload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution
securitystreamsrcememory-safety
Source: original entry ↗